Техническая информация
- 'so##dtas.us':80
- http://so##dtas.us/loader/uploads/Lima_PEDSG_Request_Specification_and_Documemation_NO.9245395838563765394835045_Lqhuhvgi.bmp
- DNS ASK so##dtas.us
- '%WINDIR%\syswow64\cmd.exe' /c timeout 20' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwADsAIABSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAiAEMAOgBcAHQAZQB3AHkAXABxAGoAegB1AHkAagBnAGIALgBlAHgAZQAiACAALQBGAG8AcgBjAGUA' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 20
- '%WINDIR%\syswow64\timeout.exe' 20
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwADsAIABSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAiAEMAOgBcAHQAZQB3AHkAXABxAGoAegB1AHkAagBnAGIALgBlAHgAZQAiACAALQBGAG8AcgBjAGUA