Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAGkAdABFAG0AIAAgACgAJwBWAEEAcgBpAEEAYgAnACsAJwBsAGUAOgAnACsAJwBrACcAKwAnAEEANwBMACcAKQAgACAAKAAgAFsAVABZAFAAZQBdACgAIgB7ADQAfQB7ADEAfQB7ADIAfQB7ADAAfQB7ADUAfQ...
- %HOMEPATH%\lzoaxa5\r_j4nup\ehyd70q_k.dll
- http://www.fu######e1.shenoydemo.org/g78zqs1w.rar
- http://ch##.robi2.hu/dvizzo.pdf
- DNS ASK fu######e1.shenoydemo.org
- DNS ASK ch##.robi2.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAGkAdABFAG0AIAAgACgAJwBWAEEAcgBpAEEAYgAnACsAJwBsAGUAOgAnACsAJwBrACcAKwAnAEEANwBMACcAKQAgACAAKAAgAFsAVABZAFAAZQBdACgAIgB7ADQAfQB7ADEAfQB7ADIAfQB7ADAAfQB7ADUAfQ...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Lzoaxa5\R_j4nup\Ehyd70q_k.dll 0