Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0AC0AdgBBAFIASQBBAEIAbABFACAAIAAoACcAMQBJACcAKwAnADYAdwBlAEwAJwApACAAKAAgAFsAVABZAFAARQBdACgAJwBzACcAKwAnAHkAJwArACcAUwB0AGUAbQAnACsAJwAuAEkAbwAnACsAJwAuAEQAaQ...
- %HOMEPATH%\s4uz2ti\mdmo8iu\z9nwl10.exe
- http://wo##uit.com/ram-aisin/7r9/
- DNS ASK wo##uit.com
- '%HOMEPATH%\s4uz2ti\mdmo8iu\z9nwl10.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0AC0AdgBBAFIASQBBAEIAbABFACAAIAAoACcAMQBJACcAKwAnADYAdwBlAEwAJwApACAAKAAgAFsAVABZAFAARQBdACgAJwBzACcAKwAnAHkAJwArACcAUwB0AGUAbQAnACsAJwAuAEkAbwAnACsAJwAuAEQAaQ...' (со скрытым окном)