Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe
- C:\temp\8chhutin.ps1
- 'ce####erholding.top':443
- 'ch####p.dyndns.org':80
- 're####freegeoip.org':443
- 'ap#.##legram.org':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d9##############
- 'ce####erholding.top':443
- 're####freegeoip.org':443
- DNS ASK ce####erholding.top
- DNS ASK ch####p.dyndns.org
- DNS ASK re####freegeoip.org
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -ep bypass -file "C:\Temp\8CHHUTIN.ps1"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -ep bypass -file "C:\Temp\8CHHUTIN.ps1" (со скрытым окном)