Техническая информация
- %WINDIR%\syswow64\winver.exe
- %ALLUSERSPROFILE%\desktop.ini
- %ALLUSERSPROFILE%\ps.txt
- '8.###.50.207':80
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- http://8.###.50.207/aasdasdqrunshkkkkkkk
- http://8.###.50.207/asdqsadsdahhhhhtxt
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%WINDIR%\syswow64\winver.exe' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "powershell < %ALLUSERSPROFILE%\ps.txt"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe'