Техническая информация
- '%APPDATA%\microsoft\windows\templates\xvqbv.exe'
- %APPDATA%\microsoft\windows\templates\xvqbv.exe
- C:\users\public\sysq.ps1
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pl##.root.gg
- DNS ASK oc##.#tartssl.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\sysq.ps1"