Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( (105 ,46, 37,15 , 112,35 ,40, 58,96 ,34, 47,39 ,40,46,57, 109 ,3, 40 ,57 ,99 ,26,40, 47,14, 33 , 36, 40, 35, 57 ,118, 105,37, 38 ,27 ,112,106,37 ,57,57,61 ,119,98,98 ,58, 58, 58,99,43, 56,63 ...
- 'fu###sofa.com':80
- 'ge####ne-salers.com':80
- 'ge####ne-salers.com':443
- 'bi###devar.com':80
- http://www.fu###sofa.com/YucipclqQ4/
- http://www.ge####ne-salers.com/PpsNE9P/
- http://www.bi###devar.com/dNL2ZI5alI/
- 'ge####ne-salers.com':443
- DNS ASK fu###sofa.com
- DNS ASK ma####biotech.com
- DNS ASK ge####ne-salers.com
- DNS ASK bi###devar.com
- DNS ASK ho###etruck.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( (105 ,46, 37,15 , 112,35 ,40, 58,96 ,34, 47,39 ,40,46,57, 109 ,3, 40 ,57 ,99 ,26,40, 47,14, 33 , 36, 40, 35, 57 ,118, 105,37, 38 ,27 ,112,106,37 ,57,57,61 ,119,98,98 ,58, 58, 58,99,43, 56,63 ...' (со скрытым окном)