Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -command $q = Get-Content -Raw -Path %TEMP%\1m.dat; $t = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($q)); Write-Output $t ;
- '<SYSTEM32>\at.exe' line:1 char:22
- %TEMP%\1m.dat
- %TEMP%\ivtm.cmd
- 're#####.herakumail.me':443
- 'ze#####.ocsp.sectigo.com':80
- http://ze#####.ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQILj%2F5BYz%2BinwYvRPv3x0WYHB6awQUyNl4aKLZGWjVPXLeXwo%2B3LWGhqYCEHbEOei%2FPbjhtDkKRrBdDvo%3D
- 're#####.herakumail.me':443
- DNS ASK re#####.herakumail.me
- DNS ASK ze#####.ocsp.sectigo.com
- '<SYSTEM32>\cmd.exe' /K %TEMP%\ivtm.cmd