Техническая информация
- %WINDIR%\microsoft.net\framework64\v4.0.30319\msbuild.exe
- %TEMP%\tmp3977.tmp.exe
- 'xl###.###nload-games-free.com':80
- 'x.#####spectrals.com':80
- http://xl###.###nload-games-free.com/file/Dxpserver.exe
- http://x.#####spectrals.com/torrent/uploads/Dxpserver_Jtrgnnho.bmp
- DNS ASK xl###.###nload-games-free.com
- DNS ASK x.#####spectrals.com
- '%TEMP%\tmp3977.tmp.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMgAwAA==' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMgAwAA==