Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\odf.vbs
- %APPDATA%\odf.exe
- '19#.#51.83.222':80
- http://19#.#51.83.222/win32/panel/uploads/Wjnzfrbuziq.wav
- 'localhost':61351
- 'localhost':59049
- 'localhost':54176
- 'localhost':62451
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /release (со скрытым окном)
- '%WINDIR%\syswow64\ipconfig.exe' /release
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAG4AYgBwAHYAcwBcAHQAdABoAGgAbAAuAGUAeABlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBF... (со скрытым окном)