Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAHCBjAG0AZAAuAGUAeABlACAALwBDACAAcwB0AGEAcgB0ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AeQBvAH...
- 'yo##ube.com':80
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- DNS ASK yo##ube.com
- DNS ASK s.##img.com
- DNS ASK fo###.gstatic.com
- DNS ASK ss#.#static.com
- DNS ASK oc##.thawte.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAHCBjAG0AZAAuAGUAeABlACAALwBDACAAcwB0AGEAcgB0ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AeQBvAH...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc SQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAHCBjAG0AZAAuAGUAeABlACAALwBDACAAcwB0AGEAcgB0ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AeQBvAHUAdAB1AGIAZQAuAGMAbwBtAC8AdwBhAHQAYwBoAD8AdgA9AGQAUQB3...
- '<SYSTEM32>\cmd.exe' /C start https://www.yo##ube.com/watch?v=###########