Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADcANwA2ADgANQAwADYAPQAnAG0AMAA3ADcAXwA5ACcAOwAkAFUAOQA3ADcAMQA1ADgAIAA9ACAAJwA1ADcAOQAnADsAJAB0ADMAMAAwADYANAAzADIAPQAnAFEAMAA3ADEAMAAxADUAJwA7ACQARwA3ADMAMgA4ADMANwA9ACQAZQBuAHYAOgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\901560.cvr
- %HOMEPATH%\579.exe
- %HOMEPATH%\579.exe
- 'mu#####spodorosario.com':80
- 'th######ppablesummit.com':80
- 'nu#####radatacenter.com':80
- http://mu#####spodorosario.com/wp-includes/6r21947/
- http://th######ppablesummit.com/wp-admin/w4bsb1t03/
- http://nu#####radatacenter.com/wp-content/upgrade/g2/
- DNS ASK gs##ow.com
- DNS ASK mu#####spodorosario.com
- DNS ASK th######ppablesummit.com
- DNS ASK nu#####radatacenter.com
- DNS ASK bl##.nakiol.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADcANwA2ADgANQAwADYAPQAnAG0AMAA3ADcAXwA5ACcAOwAkAFUAOQA3ADcAMQA1ADgAIAA9ACAAJwA1ADcAOQAnADsAJAB0ADMAMAAwADYANAAzADIAPQAnAFEAMAA3ADEAMAAxADUAJwA7ACQARwA3ADMAMgA4ADMANwA9ACQAZQBuAHYAOgB...' (со скрытым окном)