Техническая информация
- <SYSTEM32>\tasks\systeminterrupts.exe
- %TEMP%\tmp1161.tmp
- %TEMP%\tmp12d9.tmp
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-4226853953-3309226944-3078887307-1000\e1eee3f5c904006c65e465a8f5a4b5bd_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\systeminterrupts.exe
- %TEMP%\tmp1161.tmp
- %TEMP%\tmp12d9.tmp
- DNS ASK re##iver.st
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBTAHkAcwB0AGUAbQBJAG4AdABlAHIAcgB1AHAAdABzAC4AZQB4AGUAJwAgAC0AQ...