Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "IEX $env:INTERNAL_DB_CACHE;[Environment]::SetEnvironmentVariable('INTERNAL_DB_CACHE',$null,'User')"
- 'sh##x.pro':443
- '45.##.149.150':80
- 're#.##oudinary.com':443
- http://45.##.149.150/44/wcc/weneedbestpeoplesaroundonfromthegreat.hta
- 'sh##x.pro':443
- 're#.##oudinary.com':443
- DNS ASK sh##x.pro
- DNS ASK re#.##oudinary.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "IEX $env:INTERNAL_DB_CACHE;[Environment]::SetEnvironmentVariable('INTERNAL_DB_CACHE',$null,'User')" (со скрытым окном)