Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRADIAdAAzADYAeQBhAD0AKAAnAEcAJwArACgAJwBuAGcAZwAnACsAJwBxAHoAJwArACcAcAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBTAEUAUgBwAHIATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1936
- %TEMP%\1042835.cvr
- '52.##6.77.240':80
- '18.#91.1.21':80
- 'am#######llegeofeducation.com':80
- 'uf###rafo.com':443
- '5y##.com':443
- 'di####lhavayolu.com':80
- http://am#######llegeofeducation.com/css/jvFPCXM/
- http://www.di####lhavayolu.com/wp-content/mAvjTKooSP/
- 'uf###rafo.com':443
- '5y##.com':443
- DNS ASK am#######llegeofeducation.com
- DNS ASK re###ao17.com
- DNS ASK uf###rafo.com
- DNS ASK 5y##.com
- DNS ASK di####lhavayolu.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRADIAdAAzADYAeQBhAD0AKAAnAEcAJwArACgAJwBuAGcAZwAnACsAJwBxAHoAJwArACcAcAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBTAEUAUgBwAHIATw...' (со скрытым окном)